Impact
The vulnerability arises because ssl.SSLContext.wrap_bio() does not enforce the presence of a server_hostname when SSLContext.check_hostname is enabled. As a result, if the caller omits this argument, Python silently skips hostname verification instead of raising an error. This behavior can mislead developers into believing their TLS connections are properly validated while an attacker can use a forged certificate, enabling man‑in‑the‑middle attacks against applications that rely on this verification.
Affected Systems
The flaw affects Python Software Foundation CPython implementations that use SSLContext.wrap_bio(), asyncio.create_connection(), and asyncio.loop.start_tls() without supplying a non‑empty server_hostname. No specific version range is listed, so any CPython release using these APIs may be impacted if code omits the hostname argument.
Risk and Exploitability
With a CVSS score of 7.6 the severity is high, but the exploit probability (EPSS) is not reported and the vulnerability is not in the CISA KEV catalog. The attack vector is an application that incorrectly calls the affected APIs; an attacker can exploit the silent bypass by presenting a forged certificate to a client that does not supply a hostname. Since the vulnerability stems from a missing runtime check rather than a network‑exposed flaw, the likelihood depends on how often code neglects the server_hostname parameter. Nonetheless, the potential impact of enabling unauthorized communications justifies a high prioritization.
OpenCVE Enrichment