GHSA-82r6-8w77-94w6: AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
HIGHCritical vulnerability
What to do
- Critical severity — schedule an urgent patch.
### Impact Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's `connect_tcp()` or directly via `TLSStream.wrap()` where the connection has (through other means) been hijacked and redirected to a malicious server. The attacker would obtain a legitimate certificate using the IDNA 2003 encoded version of the domain name and offer it to the connecting client, making the certificate validate properly on the client's end. ### Patches The vulnerability will be patched in v4.14.2. …
CVE · detail
● loading threat intel…
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected