Echo: anyio: security update to 4.14.2

high Tenable Self-Hosted Container Security Plugin ID 462760

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio
or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and
anyio.open_process(), but open_process() forwards the group argument to the backend instead of
extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore
launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group
is also supplied, the integer group value is passed where an iterable of supplementary groups is expected
and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO
subprocess helpers to launch less-privileged child processes. This issue is fixed in version 4.14.2.
(CVE-2026-63349)

Solution

Update the anyio library and its related packages to version 4.14.2 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-63349

Plugin Details

Severity: High

ID: 462760

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.28

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-63349

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7

Threat Score: 3.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/20/2026

Vulnerability Publication Date: 9/18/2026

Reference Information

CVE: CVE-2026-63349