CVE-2026-19553
Awaiting Analysis Awaiting Analysis - Queue

SSLContext hostname verification bypass in Python

Vulnerability report for CVE-2026-19553, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Python Software Foundation

Description

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
python cpython 3.10
python cpython 3.11
python cpython 3.12
python cpython 3.13
python cpython 3.14
python cpython 3.15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-297 The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Python's SSLContext.wrap_bio() method failing to validate the server_hostname parameter properly. When ssl.SSLContext.check_hostname is enabled, the function does not enforce that server_hostname must not be None, allowing hostname verification to be silently skipped if the parameter is omitted. This could mislead developers into thinking certificate verification is active when it is not.

Detection Guidance

To detect this vulnerability, inspect Python applications using SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() without passing a valid server_hostname. Check for missing server_hostname arguments in code or logs where hostname verification should occur but doesn't raise errors.

Impact Analysis

This vulnerability could allow attackers to bypass SSL/TLS certificate hostname verification, potentially enabling man-in-the-middle attacks. Programs using SSLContext.wrap_bio() with check_hostname=True might incorrectly assume secure connections when verification is actually disabled due to missing server_hostname.

Mitigation Strategies

Mitigate by explicitly passing a valid non-None and non-empty server_hostname to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls(). This ensures hostname verification proceeds as expected without requiring Python updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19553. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart