CVE-2026-19553

NameCVE-2026-19553
Descriptionssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pypy3 (PTS)bookworm7.3.11+dfsg-2+deb12u3vulnerable
trixie7.3.19+dfsg-2vulnerable
forky, sid8.0.0+dfsg-1vulnerable
python3.11 (PTS)bookworm3.11.2-6+deb12u8vulnerable
bookworm (security)3.11.2-6+deb12u3vulnerable
python3.13 (PTS)trixie3.13.5-2+deb13u5vulnerable
forky, sid3.13.15-1vulnerable
python3.14 (PTS)forky3.14.7-4vulnerable
sid3.14.7-5vulnerable
python3.15 (PTS)forky, sid3.15.0~rc2-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pypy3source(unstable)(unfixed)
python3.11source(unstable)(unfixed)
python3.13source(unstable)(unfixed)
python3.14source(unstable)(unfixed)
python3.15source(unstable)(unfixed)

Notes

https://github.com/python/cpython/issues/156793
https://github.com/python/cpython/pull/158503
https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082 (3.15 branch)
https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced (3.14 branch)
https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062 (3.13 branch)
https://github.com/python/cpython/pull/158516 (3.11)

Search for package or bug name: Reporting problems