CRITICAL
agronholm
CVE published 2026-09-22
CVE-2026-63374
CVE-2026-63374 is a critical vulnerability in the AnyIO framework that can lead to certificate validation issues when connecting to non-ASCII domains. The issue arises from the framework's use of IDNA 2003 instead of IDNA 2008 for internationalized host name validation. This can allow an attacker to hijack or redirect connections and present a legitimate certificate for a different ASCII hostname, potenti [truncated]