SSL Certificate Verification Bypass in Python's SSL Module
CVE-2026-19553

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-19553?

A vulnerability in Python's SSL module arises from the ssl.SSLContext.wrap_bio() not enforcing a valid server_hostname when hostname validation is enabled. This oversight can lead to a situation where certificate verification appears successful, despite being improperly configured. Without a valid server_hostname value, verification is silently bypassed, potentially compromising data security. However, by ensuring that a proper non-None and non-empty server_hostname is provided to the relevant API calls, developers can effectively mitigate this issue without needing to update their Python environment.

Affected Version(s)

CPython 0 < 3.16.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

devdanzin (https://github.com/devdanzin)
Bhuvansh (https://github.com/BHUVANSH855)
Bénédikt Tran (https://github.com/picnixz)
Seth Larson (https://github.com/sethmlarson)
.