CPython CVE-2026-19445 (CVSS 9.2): ssl sni_callback context switch → use-after-free, remote crash for TLS servers — fixed 3.10.22 / 3.11.17 / 3.12.15 / 3.13.16 / 3.14.8
The Python Software Foundation announced CVE-2026-19445 on 30 September 2026 (security-announce, Seth Larson): a Critical use-after-free (CWE-416) in CPython's ssl module. A remote, unauthenticated TLS client can make a server crash or call through a freed pointer when the server's sni_callback assigns a different context to SSLSocket.context (the documented way to pick a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical exposure is servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with the context are not affected, and TLS clients are not affected. The CVE record marks CPython before 3.10.22, 3.11.0 to before 3.11.17, 3.12.0 to before 3.12.15, 3.13.0 to before 3.13.16, 3.14.0 to before 3.14.8 and 3.15.0a1 to before 3.15.0rc3 as affected. PSF scores it CVSS v4 9.2 (attack complexity high, attack requirements present). Fix: cpython PR 158504. Australia: WA Government SOC advisory 20261005002 (5 Oct) rates it Critical, notes CPython ships inside many operating systems and perimeter devices, and has no reports of exploitation on WA Government networks. NVD analysis pending.
- Product
- CPython (python.org reference interpreter) ssl module — TLS servers using sni_callback
- Versions
- Affected: before 3.10.22; 3.11.0 to before 3.11.17; 3.12.0 to before 3.12.15; 3.13.0 to before 3.13.16; 3.14.0 to before 3.14.8; 3.15.0a1 to before 3.15.0rc3 (CVE record).
- CVSS
- (CVSS v4, PSF CNA)
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Move to CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, 3.14.8 or 3.15.0rc3 or later, or your OS vendor's patched python package, and rebuild container images and bundled runtimes. Appliance and perimeter-device owners should watch vendor advisories, since CPython is often embedded. Mitigation now: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. Find exposure by searching your code for sni_callback that reassigns SSLSocket.context.
Primary: Python security-announce — CVE-2026-19445 use-after-free of server-side SSLContext when sni_callback switches contexts (30 Sep 2026) · Vendor: CVE record CVE-2026-19445 (PSF CNA; affected versions) · CVE: CVE-2026-19445 · WA Government SOC — CPython Vulnerability 20261005002 (5 Oct 2026)
