CVE-2026-19553
CVE-2026-19553 is a high-severity vulnerability with a CVSS 4.0 base score of 7.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-297.
Key facts
- Severity: High (CVSS 4.0 base score 7.6)
- EPSS exploit prediction: 0% (32nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-297
- Published:
- Last modified:
Description
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
Frequently asked questions
- What is CVE-2026-19553?
- ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
- How severe is CVE-2026-19553?
- CVE-2026-19553 has a CVSS 4.0 base score of 7.6, rated high severity.
- Is CVE-2026-19553 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (32nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-19553?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-19553 published?
- CVE-2026-19553 was published on 2026-09-30 and last updated on 2026-10-03.
References
- https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96
- https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf
- https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082
- https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed
- https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced
- https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80
- https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062
- https://github.com/python/cpython/issues/156793
- https://github.com/python/cpython/pull/158503
- https://mail.python.org/archives/list/[email protected]/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/
- http://www.openwall.com/lists/oss-security/2026/09/30/16
Other CWE-297 vulnerabilities
- CVE-2025-46408 — Critical (CVSS 9.8): An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and…
- CVE-2026-15925 — Critical (CVSS 9.2): Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have…
- CVE-2026-48144 — Critical (CVSS 9.1): Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue…
- CVE-2025-68637 — Critical (CVSS 9.1): The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default.…
- CVE-2026-35563 — High (CVSS 8.5): It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate…
- CVE-2025-3501 — High (CVSS 8.2): A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is…