Vulnerability GHSA-82r6-8w77-94w6

Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
13 days ago
September 18, 2026 at 05:17 PM UTC
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
1.0.0a1 - 4.14.1
1.0.0a1 - 4.14.1

Summary

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

Details

Impact

Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's connect_tcp() or directly via TLSStream.wrap() where the connection has (through other means) been hijacked and redirected to a malicious server. The attacker would obtain a legitimate certificate using the IDNA 2003 encoded version of the domain name and offer it to the connecting client, making the certificate validate properly on the client's end.

Patches

The vulnerability will be patched in v4.14.2.

Workarounds

Encode host names via the idna package prior to connecting.

Impacted packages

Timeline

Published
13 days ago
September 18, 2026 at 05:17 PM UTC
Fixed (4.14.2)
2 months ago
July 12, 2026 at 08:29 PM UTC
Last Modified
1 hour ago
October 01, 2026 at 05:56 PM UTC