Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-82r6-8w77-94w6 | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing |
Mon, 28 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agronholm
Agronholm anyio |
|
| Vendors & Products |
Agronholm
Agronholm anyio |
Tue, 22 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2. | |
| Title | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing | |
| Weaknesses | CWE-295 CWE-297 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-28T16:32:29.169Z
Reserved: 2026-07-16T17:39:30.170Z
Link: CVE-2026-63374
Updated: 2026-09-28T16:22:39.482Z
Status : Awaiting Analysis
Published: 2026-09-22T16:17:50.680
Modified: 2026-09-28T17:17:50.357
Link: CVE-2026-63374
No data.
OpenCVE Enrichment
Updated: 2026-09-22T17:45:17Z
Github GHSA