UBUNTU-CVE-2026-63374

Source
https://ubuntu.com/security/CVE-2026-63374
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63374.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-63374
Upstream
Published
2026-09-22T16:17:00Z
Modified
2026-09-24T02:00:49Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.

References

Affected packages

Ubuntu:22.04:LTS / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/ubuntu/python-anyio?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.2-2
3.*
3.5.0-2ubuntu1
3.5.0-3ubuntu2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-anyio",
            "binary_version":  "3.5.0-3ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63374.json"

Ubuntu:24.04:LTS / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/ubuntu/python-anyio?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.7.0-1
4.*
4.2.0-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-anyio",
            "binary_version":  "4.2.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63374.json"

Ubuntu:26.04:LTS / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/ubuntu/python-anyio?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.0-3
4.11.0-2
4.11.0-3

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-anyio",
            "binary_version":  "4.11.0-3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63374.json"