ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
https://mail.python.org/archives/list/[email protected]/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/
https://github.com/python/cpython/pull/158503
https://github.com/python/cpython/issues/156793
https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062
https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80
https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced
https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed
https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082
https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf
https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96
Published: 2026-09-30
Updated: 2026-10-02
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 5.9
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity: Medium
Base Score: 7.6
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.00472