Description
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument
to not be None if ssl.SSLContext.check_hostname was set. Due to a
missing parameter check in SSLObject, if the server_hostname argument
isn't supplied then hostname verification would be silently skipped.


This defect could lead to programs where certificate hostname verification
*appeared* to be succeeding with SSLContext.check_hostname = True and no
ValueError being raised due to misconfiguration.


If the program passes a server_hostname value that isn't an empty string
or None to any of these APIs then certificate hostname verification
proceeds as expected and the program is not affected by this vulnerability.


Mitigating this vulnerability doesn't require updating Python or applying
the patch. To mitigate, pass a valid non-None and non-empty
server_hostname value to SSLContext.wrap_bio(),
asyncio.create_connection(), or asyncio.loop.start_tls() and
certificate hostname verification will proceed as expected. Upgrading to
the latest version of Python or applying the patch only changes the
behavior from silently skipping hostname verification to raising a
ValueError, similar to SSLContext.wrap_socket(), when server_hostname
isn't supplied.
Published: 2026-09-30
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Hostname Verification Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises because ssl.SSLContext.wrap_bio() does not enforce the presence of a server_hostname when SSLContext.check_hostname is enabled. As a result, if the caller omits this argument, Python silently skips hostname verification instead of raising an error. This behavior can mislead developers into believing their TLS connections are properly validated while an attacker can use a forged certificate, enabling man‑in‑the‑middle attacks against applications that rely on this verification.

Affected Systems

The flaw affects Python Software Foundation CPython implementations that use SSLContext.wrap_bio(), asyncio.create_connection(), and asyncio.loop.start_tls() without supplying a non‑empty server_hostname. No specific version range is listed, so any CPython release using these APIs may be impacted if code omits the hostname argument.

Risk and Exploitability

With a CVSS score of 7.6 the severity is high, but the exploit probability (EPSS) is not reported and the vulnerability is not in the CISA KEV catalog. The attack vector is an application that incorrectly calls the affected APIs; an attacker can exploit the silent bypass by presenting a forged certificate to a client that does not supply a hostname. Since the vulnerability stems from a missing runtime check rather than a network‑exposed flaw, the likelihood depends on how often code neglects the server_hostname parameter. Nonetheless, the potential impact of enabling unauthorized communications justifies a high prioritization.

Generated by OpenCVE AI on September 30, 2026 at 17:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest CPython release, which validates server_hostname and raises a ValueError when the argument is missing.
  • If an upgrade is not immediately possible, modify all SSLContext.wrap_bio(), asyncio.create_connection(), and asyncio.loop.start_tls() invocations to provide a non‑empty, non‑None server_hostname so that hostname verification proceeds normally.
  • Audit existing code for omitted hostname arguments and add defensive wrappers or checks to guarantee that server_hostname is supplied before any TLS handshake occurs.

Generated by OpenCVE AI on September 30, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
Title SSLContext.wrap_bio() missing validation of server_hostname parameter
Weaknesses CWE-297
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: PSF

Published:

Updated: 2026-09-30T16:17:39.368Z

Reserved: 2026-08-11T15:22:03.833Z

Link: CVE-2026-19553

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T17:16:45.880

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-19553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses
  • CWE-297

    Improper Validation of Certificate with Host Mismatch