OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63374

CRITICAL · CVSS 9.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

AnyIO versions prior to 4.14.2 are vulnerable to a critical issue where the connect_tcp() and TLSStream.wrap() functions improperly validate internationalized host names using the outdated IDNA 2003 standard. This flaw allows attackers to hijack or redirect connections to non-ASCII domains, potentially enabling them to present a valid certificate for a malicious endpoint, thereby compromising secure communications. Organizations utilizing AnyIO for asynchronous networking should prioritize upgrading to version 4.14.2 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63374
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%

Original NVD Description

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.