{"id":"CVE-2026-19553","title":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set","summary":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname ve…","severity":"high","cvss":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-297"],"vendor":"Python Software Foundation","product":"CPython","affected":["CPython < 3.16.0"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T19:16:40.923","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","references":[{"url":"https://github.com/python/cpython/issues/156793","label":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/158503","label":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","label":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/16","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-30T17:13:20.841Z","slug":"CVE-2026-19553","body":"## Overview\n\nssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}