CVE-2026-19445EPSS p35.0%
CVE-2026-19445CVE-2026-19445
Description
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.
Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.
Scoring
| EPSS | 0.43% probability of exploitation · percentile 35.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-03 |