CRITICAL GitHub
CVE-2026-63374
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
### Impact
Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's `connect_tcp()` or directly via `TLSStream.wrap()` where the connection has (through other means) been hijacked and redirected to a malicious server. The attacker would obtain a legitimate certificate using the IDNA 2003 encoded version of the domain name and offer it to the connecting client, making the certificate validate properly on the client's end.
### Patch
Affected Products
- pip/anyio < 4.14.2
References
- https://github.com/advisories/GHSA-82r6-8w77-94w6
- https://github.com/agronholm/anyio/security/advisories/GHSA-82r6-8w77-94w6
- https://github.com/agronholm/anyio/pull/1208
- https://github.com/agronholm/anyio/commit/68f58915f82d9be8109ebbbd8f5d70577d43f2ce
This critical severity vulnerability was published on 2026-09-18 via GitHub. Affected: pip/anyio < 4.14.2.
vulnfeed aggregates 14649 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.