{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/anyio-4.14.0-4.14.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AnyIO (\u003c 4.14.2)","AnyIO (4.14.0, 4.14.1)"],"_cs_severities":["critical"],"_cs_tags":["privilege-escalation","vulnerability","python","linux"],"_cs_type":"advisory","_cs_vendors":["AnyIO"],"content_html":"\u003cp\u003eAnyIO (CVE-2026-63374) contains a vulnerability in its TLSStream implementation related to the handling of internationalized domain names (IDNs). The library incorrectly relies on the deprecated IDNA 2003 standard for host name encoding. If an application uses AnyIO's \u003ccode\u003econnect_tcp()\u003c/code\u003e or \u003ccode\u003eTLSStream.wrap()\u003c/code\u003e to connect to an internationalized domain, an attacker capable of hijacking or redirecting the network connection can exploit this discrepancy. By obtaining a legitimate TLS certificate using the IDNA 2003 encoding of the intended host name, the attacker can present this certificate to the AnyIO client. The client, utilizing the same outdated encoding logic, validates the malicious certificate as authentic for the intended domain. This vulnerability facilitates potential man-in-the-middle (MITM) attacks for services relying on AnyIO for outbound connections to internationalized domains.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a critical risk to applications using AnyIO that perform outbound connections to internationalized host names. Successful exploitation allows for the complete bypass of TLS certificate validation, enabling attackers to intercept, inspect, or modify sensitive data transmitted between the client and the intended server. Organizations operating services that communicate with diverse global domains are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003eanyio\u003c/code\u003e package to version 4.14.2 or later immediately.\u003c/li\u003e\n\u003cli\u003eAs a temporary workaround, manually encode host names using the modern \u003ccode\u003eidna\u003c/code\u003e package prior to passing them to AnyIO connection methods to ensure compatibility with modern standards.\u003c/li\u003e\n\u003cli\u003eAudit application code to identify calls to \u003ccode\u003econnect_tcp()\u003c/code\u003e or \u003ccode\u003eTLSStream.wrap()\u003c/code\u003e that handle user-provided or dynamic internationalized host names.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T07:44:57Z","date_published":"2026-09-18T19:48:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-anyio-tls-spoofing/","summary":"AnyIO versions prior to 4.14.2 are vulnerable to TLS certificate spoofing when using IDNA 2003 encoded internationalized domain names, allowing an attacker who redirects traffic to present a domain-validated certificate that the client incorrectly trusts.","title":"AnyIO TLS Certificate Spoofing via IDNA 2003 Encoding","url":"https://feed.craftedsignal.io/briefs/2026-09-anyio-tls-spoofing/"}],"language":"en","title":"CraftedSignal Threat Feed - AnyIO (4.14.0, 4.14.1)","version":"https://jsonfeed.org/version/1.1"}