CVE-2026-19553 is a CPython TLS certificate hostname-validation flaw in ssl.SSLContext.wrap_bio(). When SSLContext.check_hostname is enabled, the affected SSLObject path does not require server_hostname to be non-None. If a caller omits the server_hostname value, hostname verification is silently skipped rather than failing, even though the application may appear to have enabled hostname checking. The affected usage also includes asyncio.create_connection() and asyncio.loop.start_tls() when invoked without a valid non-empty server hostname.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone Python proof-of-concept repository for CVE-2026-19553 (CWE-297), not a Metasploit/Nuclei-style framework module. The root launcher, cve-2026-19553-wrap-bio-Abraxas-Labs.py, changes into lab/ and invokes lab/run.sh. The runner builds a pinned python:3.14.7-slim-bookworm Docker image, runs lab/poc.py in the container, records output to poc-last-run.txt, and falls back to the host Python interpreter if Docker Compose cannot start. The primary PoC uses a locally generated CA and two leaf certificates, victim.lab and evil.lab. It configures a client context with certificate-chain validation and hostname checking enabled, then exercises MemoryBIO/SSLObject wrap_bio paths. The injection condition calls wrap_bio with server_hostname=None while the simulated server presents evil.lab; vulnerable CPython accepts the handshake despite the absent identity check. Control cases establish that wrap_socket with no hostname raises ValueError, an explicit victim.lab name rejects evil.lab with SSLCertVerificationError, and the matching victim.lab certificate succeeds. An additional asyncio server/client test on 127.0.0.1:18510 demonstrates that asyncio.open_connection with server_hostname='' becomes the same missing-hostname condition. The code contains no shell, command-execution, persistence, credential-theft, or post-exploitation payload; its capability is limited to demonstrating a TLS peer-identity verification bypass under the required MITM/attacker-server conditions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unspecified security vulnerability in the Python interpreter addressed by the Python 3.14.8 Fedora 43 update.
A security vulnerability in the Python interpreter addressed by the python3.14-3.14.8-1.fc44 Fedora 44 update. The specific vulnerability type and impact are not described.
A Python SSLObject/SSLContext hostname-verification bypass caused by a missing validation of server_hostname in SSLContext.wrap_bio(). Applications using check_hostname=True but omitting server_hostname could silently skip TLS certificate hostname validation rather than receiving a configuration error.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.