SSL Certificate Verification Bypass in Python's SSL Module
CVE-2026-19553
7.6HIGH
What is CVE-2026-19553?
A vulnerability in Python's SSL module arises from the ssl.SSLContext.wrap_bio() not enforcing a valid server_hostname when hostname validation is enabled. This oversight can lead to a situation where certificate verification appears successful, despite being improperly configured. Without a valid server_hostname value, verification is silently bypassed, potentially compromising data security. However, by ensuring that a proper non-None and non-empty server_hostname is provided to the relevant API calls, developers can effectively mitigate this issue without needing to update their Python environment.
Affected Version(s)
CPython 0 < 3.16.0
References
CVSS V4
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
devdanzin (https://github.com/devdanzin)
Bhuvansh (https://github.com/BHUVANSH855)
Bénédikt Tran (https://github.com/picnixz)
Seth Larson (https://github.com/sethmlarson)
