
Upwind Security MDR@UpwindMDR
🚨Critical - AnyIO TLS IDNA Hostname Validation Bypass (CVE-2026-63374) AnyIO mishandles internationalized (non-ASCII) domain names in TLS connections via connect_tcp() and TLSStream.wrap(). If an attacker hijacks/redirects traffic, they can present a cert for the IDNA 2003-encoded hostname that still validates, enabling TLS certificate spoofing against clients. ASCII-only hostnames are not affected. 👉Affected: anyio < 4.14.2 | Upgrade to 4.14.2
1001028
304 followersView on X
