|
|
Message-ID: <16c22653-f977-4271-8b22-1f10767259cb@oracle.com> Date: Wed, 30 Sep 2026 09:56:07 -0700 From: Alan Coopersmith <alan.coopersmith@...cle.com> To: oss-security@...ts.openwall.com Subject: CPython [CVE-2026-19553] SSLContext.wrap_bio() missing validation of server_hostname parameter -------- Forwarded Message -------- Subject: [Security-announce][CVE-2026-19553] SSLContext.wrap_bio() missing validation of server_hostname parameter Date: Wed, 30 Sep 2026 16:08:09 +0000 From: Seth Larson <seth@...hon.org> Reply-To: security-sig@...hon.org To: security-announce@...hon.org There is a HIGH severity vulnerability affecting CPython. `ssl.SSLContext.wrap_bio()` didn't require the `server_hostname` argument to not be `None` if `ssl.SSLContext.check_hostname` was set. Due to a missing parameter check in `SSLObject`, if the `server_hostname` argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with `SSLContext.check_hostname = True` and no `ValueError` being raised due to misconfiguration. If the program passes a `server_hostname` value that isn't an empty string or `None` to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-`None` and non-empty `server_hostname` value to `SSLContext.wrap_bio()`, `asyncio.create_connection()`, or `asyncio.loop.start_tls()` and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a `ValueError`, similar to `SSLContext.wrap_socket()`, when `server_hostname` isn't supplied. Please see the linked CVE ID for the latest information on affected versions: * https://www.cve.org/CVERecord?id=CVE-2026-19553 * https://github.com/python/cpython/pull/158503 _______________________________________________ Security-announce mailing list -- security-announce@...hon.org https://mail.python.org/mailman3//lists/security-announce.python.org
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.