
CVE-2026-19445 hits Python Software Foundation's CPython, CVSS 9.2. A remote unauthenticated TLS client can crash the server or hit a use-after-free by making its sni_callback swap SSLContext, no valid cert or auth needed. VulnTracker recommends upgrading CPython immediately, servers that create or replace an SSLContext per connection are the ones exposed. Details:http://vulntracker.io/cves/CVE-2026-19445 #Python #CPython #CVE #InfoSec

