CVE-2026-19445

Published: Set 30, 2026 Last Modified: Ott 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,2
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.

Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0051
Percentile
0,4th
Updated

Single Data Point

Only one EPSS measurement is available for this CVE. Trend analysis requires multiple data points over time.

416

Use After Free

Stable
Common Consequences
Security Scopes Affected:
Integrity Availability Confidentiality
Potential Impacts:
Modify Memory Dos: Crash, Exit, Or Restart Read Memory Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: Memory-Unsafe, C, C++
View CWE Details
http://www.openwall.com/lists/oss-security/2026/09/30/17
https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a1005…
https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac55…
https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44a…
https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4b…
https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf36…
https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e…
https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef2…
https://github.com/python/cpython/issues/156293
https://github.com/python/cpython/pull/158504
https://mail.python.org/archives/list/[email protected]/thread/QMQIU…