Bug 2538958 (CVE-2026-63374)

Summary: CVE-2026-63374 anyio: AnyIO: TLS certificate spoofing via improper internationalized domain name encoding
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: alinfoot, anpicker, anthomas, aprice, bbrownin, blitton, bparees, dfreiber, dkeler, doconnor, drow, dschmidt, dtrifiro, dymurray, ebourniv, eglynn, ehelms, gbenhaim, ggainey, hasun, ibolton, ikhan, ilpinto, jburrell, jdobes, jfula, jjoyce, jlanda, jmatthew, jmitchel, jmontleo, jowilson, jpasqual, jpretori, jsamir, jschluet, juwatts, jwong, kaycoth, kgaikwad, kshier, lhh, ltomasbo, mbarnett, mburns, mdellweg, mgarciac, mhayden, mhulan, niyer, nmoumoul, nyancey, oezr, omaciel, ometelka, orabin, osousa, pcreech, pgaikwad, prwatson, ptisnovs, rbobbitt, rchan, rekumar, rjohnson, sbunciak, sdoran, simaishi, slucidi, smallamp, sseago, stcannon, suppawar, syedriko, thason, tmalecek, ttakamiy, twaugh, vkumar, vvoronko, weaton, xdharmai, yguenane, ykashtan
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in AnyIO. A remote attacker in a privileged network position can bypass Transport Layer Security (TLS) certificate validation when connecting to internationalized domain names. This vulnerability occurs because the framework converts internationalized hostnames using an outdated encoding standard, Internationalizing Domain Names in Applications (IDNA) 2003 instead of IDNA 2008. If network traffic is redirected or intercepted, an attacker can present a legitimate certificate for the mismatched domain name, allowing them to impersonate the intended server and intercept or alter sensitive communications.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-22 21:50:08 UTC
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.