DEBIAN-CVE-2026-63374

Source
https://security-tracker.debian.org/tracker/CVE-2026-63374
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63374.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-63374
Upstream
Published
2026-09-22T16:17:50Z
Modified
2026-09-23T05:01:21Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.

References

Affected packages

Debian:12 / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/debian/python-anyio?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.2-1
3.7.0-1
4.*
4.1.0-1
4.2.0-1
4.3.0-1
4.4.0-1
4.6.0-1
4.6.2-1
4.6.2-2
4.6.2-3
4.6.2-4
4.7.0-1
4.8.0-1
4.8.0-2
4.8.0-3
4.11.0-1
4.11.0-2
4.11.0-3
4.12.1-1
4.12.1-2
4.12.1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63374.json"

Debian:13 / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/debian/python-anyio?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.0-3
4.11.0-1
4.11.0-2
4.11.0-3
4.12.1-1
4.12.1-2
4.12.1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63374.json"

Debian:14 / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/debian/python-anyio?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.0-3
4.11.0-1
4.11.0-2
4.11.0-3
4.12.1-1
4.12.1-2
4.12.1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63374.json"