CVE-2026-19553

high

Description

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.

References

https://mail.python.org/archives/list/[email protected]/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/

https://github.com/python/cpython/pull/158503

https://github.com/python/cpython/issues/156793

https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062

https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80

https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced

https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed

https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082

https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf

https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90078

http://www.openwall.com/lists/oss-security/2026/09/30/16

Details

Source: Mitre, NVD

Published: 2026-09-30

Updated: 2026-10-02

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.9

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: Medium

CVSS v4

Base Score: 7.6

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00472