anyio vulnerabilities
CVEs whose affected-version data names the anyio package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-64847Medium· 6.8AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…
CVE-2026-63374CriticalAnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
CVE-2026-63349High· 7.0AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…