Critical severity9.3NVD Advisory· Published Sep 18, 2026· Updated Sep 18, 2026
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
CVE-2026-63374
Description
Impact
Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's connect_tcp() or directly via TLSStream.wrap() where the connection has (through other means) been hijacked and redirected to a malicious server. The attacker would obtain a legitimate certificate using the IDNA 2003 encoded version of the domain name and offer it to the connecting client, making the certificate validate properly on the client's end.
Patches
The vulnerability will be patched in v4.14.2.
Workarounds
Encode host names via the idna package prior to connecting.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.