CRITICAL GitHub

CVE-2026-63374

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

### Impact Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's `connect_tcp()` or directly via `TLSStream.wrap()` where the connection has (through other means) been hijacked and redirected to a malicious server. The attacker would obtain a legitimate certificate using the IDNA 2003 encoded version of the domain name and offer it to the connecting client, making the certificate validate properly on the client's end. ### Patch

Affected Products

References

Published: 2026-09-18 · Source: GitHub · Feed updated: 2026-09-18
This critical severity vulnerability was published on 2026-09-18 via GitHub. Affected: pip/anyio < 4.14.2.
vulnfeed aggregates 14649 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.