CyberRota Analysis
AI-GeneratedAnyIO versions prior to 4.14.2 are vulnerable to a critical issue where the connect_tcp() and TLSStream.wrap() functions improperly validate internationalized host names using the outdated IDNA 2003 standard. This flaw allows attackers to hijack or redirect connections to non-ASCII domains, potentially enabling them to present a valid certificate for a malicious endpoint, thereby compromising secure communications. Organizations utilizing AnyIO for asynchronous networking should prioritize upgrading to version 4.14.2 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.