{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-19445","assignerOrgId":"28c92f92-d60d-412d-b760-e73465c3df22","state":"PUBLISHED","assignerShortName":"PSF","dateReserved":"2026-08-10T13:31:21.724Z","datePublished":"2026-09-30T16:16:04.923Z","dateUpdated":"2026-10-03T00:36:46.398Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","modules":["ssl"],"product":"CPython","repo":"https://github.com/python/cpython","vendor":"Python Software Foundation","versions":[{"version":"0","lessThan":"3.10.22","status":"affected","versionType":"python"},{"version":"3.11.0","lessThan":"3.11.17","status":"affected","versionType":"python"},{"version":"3.12.0","lessThan":"3.12.15","status":"affected","versionType":"python"},{"version":"3.13.0","lessThan":"3.13.16","status":"affected","versionType":"python"},{"version":"3.14.0","lessThan":"3.14.8","status":"affected","versionType":"python"},{"version":"3.15.0a1","lessThan":"3.15.0rc3","status":"affected","versionType":"python"}]}],"credits":[{"lang":"en","type":"reporter","value":"Gregory P. Smith (https://github.com/gpshead)"},{"lang":"en","type":"coordinator","value":"Seth Larson (https://github.com/sethmlarson)"},{"lang":"en","type":"remediation reviewer","value":"Bénédikt Tran (https://github.com/picnixz)"}],"descriptions":[{"lang":"en","supportingMedia":[{"type":"text/html","value":"<p>A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.</p>\n<p>Mitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected.</p>"}],"value":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.2,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-416","description":"CWE-416","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"28c92f92-d60d-412d-b760-e73465c3df22","shortName":"PSF","dateUpdated":"2026-10-03T00:36:46.398Z"},"references":[{"tags":["patch"],"url":"https://github.com/python/cpython/pull/158504"},{"tags":["vendor-advisory"],"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/"},{"tags":["issue-tracking"],"url":"https://github.com/python/cpython/issues/156293"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b"}],"source":{"discovery":"UNKNOWN"},"title":"Use-after-free of a server-side SSLContext when sni_callback switches contexts","x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/17"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-30T18:09:39.735Z"}}]}}