天下漏洞,尽知其名
HIGH

CVE-2026-19445 Python SSLContext 释放后使用漏洞

公开 PoC

nvd.nist.gov/vuln/detail/CVE-2026-19445

原始情报

A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.

Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.

其他来源(1)