TL;DR
On September 30, 2026, the Python Software Foundation disclosed two security flaws in CPython. These critical Python SSL vulnerabilities allow memory corruption and bypass certificate hostname verification. Developers must update their Python installations or apply immediate configuration changes to protect their servers.
- Product: Python Software Foundation CPython
- Vulnerabilities: 2 flaws (CVE-2026-19445, CVE-2026-19553)
- Highest severity: 9.2 (Critical · CVSSv4)
- Worst impact: Use-after-free of a server-side SSLContext when sni_callback switches contexts
- Status: No confirmed exploitation yet; patches available
- Action: Update to 3.12.15, 3.13.16, 3.14.8, 3.15.0 now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-19445 | 9.2 | Use-after-free of a server-side SSLContext when sni_callback switches contexts | 3.12.15, 3.13.16, 3.14.8 (+1) | Not exploited |
| CVE-2026-19553 | 7.6 | SSLContext.wrap_bio() missing validation of server_hostname parameter | 3.12.15, 3.13.16, 3.14.8 (+1) | Not exploited |
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
Sourced industry estimates show that millions of backend services and web applications rely on Python. Consequently, flaws in core networking libraries introduce substantial risks to cloud infrastructure. The primary flaw carries a critical CVSS base score of 9.2. An unauthenticated remote attacker can exploit this defect to crash servers or execute malicious commands. Meanwhile, the secondary issue carries a high CVSS rating of 7.6. Currently, security teams have confirmed no active exploitation in the wild. Additionally, researchers have not published any public proof-of-concept exploit code. However, unpatched servers remain exposed to silent security failures. Therefore, resolving these Python SSL vulnerabilities remains vital for production systems.
How The Attack Works
The two vulnerabilities target distinct functions within the core SSL module. The critical flaw, CVE-2026-19445, involves a use-after-free condition. When a TLS client connects, the server invokes the Server Name Indication callback. If this callback switches contexts and nothing holds the original context alive, the memory frees prematurely. As a result, the server calls through a dangling pointer during the handshake.
In contrast, CVE-2026-19553 affects certificate verification logic. The wrap_bio function omitted validation checks for the server hostname parameter. If a developer sets check_hostname to true but omits the hostname, Python silently skips verification. Consequently, the client accepts untrusted certificates without raising an error.
Affected Versions
These security issues affect multiple active release branches of CPython. Vulnerable releases include versions prior to 3.12.15, 3.13.16, 3.14.8, and 3.15.0.
Patch Or Mitigation Steps
Administrators should update their environments to patched releases immediately. For the use-after-free flaw, review the official Python security advisory for CVE-2026-19445. To mitigate this issue without upgrading, retain a persistent reference to every SSLContext using an SNI callback.
Additionally, examine the Python advisory for CVE-2026-19553 to address hostname validation failures. Developers can mitigate the verification flaw by passing a valid, non-empty server hostname to wrap_bio. Applying these updates eliminates the threat of these Python SSL vulnerabilities across enterprise deployments.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!