THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-82r6-8w77-94w6 (critical) — AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

[GHSA] GHSA-82r6-8w77-94w6 (critical) — AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

medgithub_advisoriesPublished 2026-09-18

GHSA-82r6-8w77-94w6 Severity: critical CVE: CVE-2026-63374

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

### Impact Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's `connect_tcp()` or directly via `TLSStream.wrap()` where the connection has (through other means) been hijacked and r

Indicators of compromise

Original source: https://github.com/advisories/GHSA-82r6-8w77-94w6