CVE-2026-19445 | A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Miti
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.
Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.
- 🔗 github.com/python/cpython/pull/158504
- 🔗 mail.python.org/archives/list/[email protected]…
- 🔗 github.com/python/cpython/issues/156293
- 🔗 github.com/python/cpython/commit/34a53dce8174da2fceb…
- 🔗 github.com/python/cpython/commit/46133cd57d309652139…
- 🔗 github.com/python/cpython/commit/63fab143d94cafae718…
- 🔗 github.com/python/cpython/commit/cd7e51e7d4563866fba…
- 🔗 github.com/python/cpython/commit/d8717ed01717a964168…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-20 | 2026-10-04 |
|---|---|---|
| ≥90 % | 489 | 361 |
| ≥50 % | 1477 | 1099 |
| ≥10 % | 0 | 2 |
| <10 % | 0 | 505 |
CVE-2026-19445 | A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Miti
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else
Noch keine Analyse zu CVE-2026-19445
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.