ON 30 September 2026, the Python Software Foundation disclosed two critical flaws in CPython’s SSL module (CVE-2026-19445 and CVE-2026-19553) that could lead to memory corruption and a bypass of certificate hostname verification. The first issue is a use-after-free in the server-side SSLContext during TLS handshakes when an SNI callback switches contexts, potentially dereferencing a freed pointer.
The second flaw involves the wrap_bio() function omitting validation of the server_hostname parameter when check_hostname is enabled, allowing untrusted certificates to be accepted without error. The vulnerabilities affect multiple active CPython release lines, with vulnerable builds prior to 3.12.15, 3.13.16, 3.14.8, and 3.15.0.
Evidence and practical response indicate these are currently not known to be exploited in the wild, and patches are available. The highest severity is CVSS v4 base 9.2 for CVE-2026-19445 and 7.6 for CVE-2026-19553. To mitigate, administrators should upgrade to patched releases: CPython 3.12.15, 3.13.16, 3.14.8, or 3.15.0 (or newer). As an interim measure, for the use-after-free flaw one can retain a persistent reference to every SSLContext using an SNI callback.
For the hostname verification issue, ensure wrap_bio is invoked with a valid, non-empty server_hostname. Implementing these updates will mitigate the vulnerabilities across enterprise deployments.