CVE-2026-19553
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.
This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.
If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.
Leer descripción completaMostrar menos
Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 7.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution45 % - Impacto principal
T1557Adversary-in-the-Middlecredential access · collection70 % - Impacto secundario
T1040Network Sniffingcredential access · discovery65 %
AV:N con UI:P sugiere interacción del usuario en cliente (T1203). La vulnerabilidad permite bypass de verificación SSL/TLS, facilitando ataques MITM (T1557) e intercepción de datos (T1040) si no se valida hostname.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-297
Referencias
- https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96
- https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf
- https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082
- https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed
- https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced
- https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80
- https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062
- https://github.com/python/cpython/issues/156793
- https://github.com/python/cpython/pull/158503
- https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/
- http://www.openwall.com/lists/oss-security/2026/09/30/16
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-19553",
"cveTags": [],
"metrics": {
"cvssMetricV40": [
{
"type": "Secondary",
"source": "cna@python.org",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 7.6,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "PASSIVE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "cna@python.org",
"affectedData": [
{
"repo": "https://github.com/python/cpython",
"vendor": "Python Software Foundation",
"modules": [
"ssl"
],
"product": "CPython",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.10.22",
"versionType": "python"
},
{
"status": "affected",
"version": "3.11.0",
"lessThan": "3.11.17",
"versionType": "python"
},
{
"status": "affected",
"version": "3.12.0",
"lessThan": "3.12.15",
"versionType": "python"
},
{
"status": "affected",
"version": "3.13.0",
"lessThan": "3.13.16",
"versionType": "python"
},
{
"status": "affected",
"version": "3.14.0",
"lessThan": "3.14.8",
"versionType": "python"
},
{
"status": "affected",
"version": "3.15.0a1",
"lessThan": "3.15.0rc3",
"versionType": "python"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-30T17:16:45.880",
"references": [
{
"url": "https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/issues/156793",
"source": "cna@python.org"
},
{
"url": "https://github.com/python/cpython/pull/158503",
"source": "cna@python.org"
},
{
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/",
"source": "cna@python.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/30/16",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@python.org",
"description": [
{
"lang": "en",
"value": "CWE-297"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."
}
],
"lastModified": "2026-10-03T01:17:25.090",
"sourceIdentifier": "cna@python.org"
}