CVE-2026-63374

Source
https://cve.org/CVERecord?id=CVE-2026-63374
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63374.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-63374
Aliases
Downstream
CGA (29)
CLSA (1)
DEBIAN (1)
MINI (21)
ROOT (1)
UBUNTU (1)
Published
2026-09-22T15:23:14Z
Modified
2026-09-23T03:47:31Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
Details

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-295",
        "CWE-297"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63374.json"
}
References

Affected packages

Git / github.com/agronholm/anyio

Affected ranges

Type
GIT
Repo
https://github.com/agronholm/anyio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "4.14.2"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
2.*
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
3.*
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
3.6.0
3.6.1
4.*
4.0.0
4.0.0rc1
4.1.0
4.10.0
4.11.0
4.12.0
4.13.0
4.14.0
4.14.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.2.post1
4.7.0
4.8.0
4.9.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63374.json"