EUVD Vulnerability Catalog
EUVD-2026-90077
Severity: CRITICAL
Base Score: 9.2
CVSS Version: 4.0
Vulnerability Description
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.
Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): High
▪
Attack Requirements (AT): Present
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Vulnerability Confidentiality Impact (VC): High
▪
Vulnerability Integrity Impact (VI): High
▪
Vulnerability Availability Impact (VA): Low
▪
Subsequent Confidentiality Impact (SC): None
▪
Subsequent Integrity Impact (SI): None
▪
Subsequent Availability Impact (SA): None
Affected Vendors & Systems
Vendor
Python Software Foundation
References & Advisory Links
- https://github.com/python/cpython/pull/158504
- https://mail.python.org/archives/list/[email protected]/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/
- https://github.com/python/cpython/issues/156293
- https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d
- https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b
- https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7
- https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698
- https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c
- https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8
- https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
PSF
EPSS Probability
0
Known Aliases
CVE-2026-19445
GHSA-7jvw-f348-84gq
Published On
2026-09-30
Last Updated
2026-10-01