OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-19445

CRITICAL · CVSS 9.2 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A vulnerability exists in servers that improperly manage SSLContext references when using the sni_callback function, allowing a remote, unauthenticated TLS client to crash the server or exploit a freed pointer. This critical issue primarily impacts servers that create or replace SSLContext instances per connection without maintaining a reference to the original context. Organizations operating such servers should prioritize immediate remediation to prevent potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19445
Severity
CRITICAL
CVSS
9.2
EPSS
0.43%

Original NVD Description

A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected.