CVE-2026-19445: CWE-416 in Python Software Foundation CPython
CVE-2026-19445 is a critical use-after-free vulnerability (CWE-416) in CPython's SSL handling. A remote, unauthenticated TLS client can cause a server crash or execute code through a freed pointer if the server's sni_callback assigns a different SSLContext to SSLSocket.context and the original SSLContext is not kept alive. This typically affects servers that create or replace SSLContext objects per connection. TLS clients are not impacted by this vulnerability.
AI Analysis
Technical Summary
This vulnerability arises when a server using CPython's SSL module assigns a new SSLContext in the sni_callback without maintaining a reference to the original SSLContext. If the original SSLContext is freed while still in use, a remote TLS client can trigger a crash or use-after-free condition. Servers that create or replace SSLContext objects per connection are vulnerable, whereas those wrapping their listening socket with a persistent SSLContext are not affected.
Potential Impact
A remote, unauthenticated attacker can cause a denial of service by crashing the server or potentially execute code through use-after-free of SSLContext objects. The vulnerability does not affect TLS clients.
Mitigation Recommendations
Keep a reference to every SSLContext that sets sni_callback for the lifetime of the server to prevent the original SSLContext from being freed prematurely. This mitigation is effective and no official patch is indicated in the provided data. TLS clients require no action.
CVE-2026-19445: CWE-416 in Python Software Foundation CPython
Description
CVE-2026-19445 is a critical use-after-free vulnerability (CWE-416) in CPython's SSL handling. A remote, unauthenticated TLS client can cause a server crash or execute code through a freed pointer if the server's sni_callback assigns a different SSLContext to SSLSocket.context and the original SSLContext is not kept alive. This typically affects servers that create or replace SSLContext objects per connection. TLS clients are not impacted by this vulnerability.
CVSS v4.0
Score 9.2critical
Affected software
Python Software Foundation
CPython
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises when a server using CPython's SSL module assigns a new SSLContext in the sni_callback without maintaining a reference to the original SSLContext. If the original SSLContext is freed while still in use, a remote TLS client can trigger a crash or use-after-free condition. Servers that create or replace SSLContext objects per connection are vulnerable, whereas those wrapping their listening socket with a persistent SSLContext are not affected.
Potential Impact
A remote, unauthenticated attacker can cause a denial of service by crashing the server or potentially execute code through use-after-free of SSLContext objects. The vulnerability does not affect TLS clients.
Mitigation Recommendations
Keep a reference to every SSLContext that sets sni_callback for the lifetime of the server to prevent the original SSLContext from being freed prematurely. This mitigation is effective and no official patch is indicated in the provided data. TLS clients require no action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PSF
- Date Reserved
- 2026-08-10T13:31:21.724Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd3d882a4e24523d41fc81
Added to database: 09/30/2026, 16:49:12 UTC
Last enriched: 09/30/2026, 17:03:12 UTC
Last updated: 09/30/2026, 17:03:12 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.