CVE Vulnerabilities

CVE-2026-63374

Improper Certificate Validation

Published: Sep 22, 2026 | Modified: Sep 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoints certificate to validate. This issue is fixed in version 4.14.2.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:1790621718*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:1790621713*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/mcp-tools-rhel9:1790931895*

Potential Mitigations

References