Vulnerable Library - anyio-4.6.0-py3-none-any.whl
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (anyio version) |
Remediation Possible** |
| CVE-2026-63374 |
Critical |
9.1 |
anyio-4.6.0-py3-none-any.whl |
Direct |
4.14.2 |
❌ |
| CVE-2026-63349 |
Medium |
5.7 |
anyio-4.6.0-py3-none-any.whl |
Direct |
4.14.2 |
❌ |
| CVE-2026-64847 |
Medium |
5.5 |
anyio-4.6.0-py3-none-any.whl |
Direct |
4.14.2 |
❌ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-63374
Vulnerable Library - anyio-4.6.0-py3-none-any.whl
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Dependency Hierarchy:
- ❌ anyio-4.6.0-py3-none-any.whl (Vulnerable Library)
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Found in base branch: develop
Vulnerability Details
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.
Publish Date: 2026-09-22
URL: CVE-2026-63374
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-18
Fix Resolution: 4.14.2
Step up your Open Source Security Game with Mend here
CVE-2026-63349
Vulnerable Library - anyio-4.6.0-py3-none-any.whl
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Dependency Hierarchy:
- ❌ anyio-4.6.0-py3-none-any.whl (Vulnerable Library)
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Found in base branch: develop
Vulnerability Details
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in version 4.14.2.
Publish Date: 2026-09-18
URL: CVE-2026-63349
CVSS 3 Score Details (5.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-18
Fix Resolution: 4.14.2
Step up your Open Source Security Game with Mend here
CVE-2026-64847
Vulnerable Library - anyio-4.6.0-py3-none-any.whl
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Dependency Hierarchy:
- ❌ anyio-4.6.0-py3-none-any.whl (Vulnerable Library)
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Found in base branch: develop
Vulnerability Details
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains, even though the documented behavior redirects all three standard streams. Worker code that writes enough attacker-influenced data to sys.stderr can fill the pipe and block before returning the standard-output protocol response, causing the awaiting process-pool call to remain blocked indefinitely. Applications that run untrusted or faulty worker code capable of producing substantial standard-error output are affected. This issue is fixed in version 4.14.2.
Publish Date: 2026-09-18
URL: CVE-2026-64847
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-18
Fix Resolution: 4.14.2
Step up your Open Source Security Game with Mend here
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - anyio-4.6.0-py3-none-any.whl
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Dependency Hierarchy:
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Found in base branch: develop
Vulnerability Details
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.
Publish Date: 2026-09-22
URL: CVE-2026-63374
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-09-18
Fix Resolution: 4.14.2
Step up your Open Source Security Game with Mend here
Vulnerable Library - anyio-4.6.0-py3-none-any.whl
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Dependency Hierarchy:
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Found in base branch: develop
Vulnerability Details
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in version 4.14.2.
Publish Date: 2026-09-18
URL: CVE-2026-63349
CVSS 3 Score Details (5.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-09-18
Fix Resolution: 4.14.2
Step up your Open Source Security Game with Mend here
Vulnerable Library - anyio-4.6.0-py3-none-any.whl
High level compatibility layer for multiple asynchronous event loop implementations
Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl
Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt
Dependency Hierarchy:
Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389
Found in base branch: develop
Vulnerability Details
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains, even though the documented behavior redirects all three standard streams. Worker code that writes enough attacker-influenced data to sys.stderr can fill the pipe and block before returning the standard-output protocol response, causing the awaiting process-pool call to remain blocked indefinitely. Applications that run untrusted or faulty worker code capable of producing substantial standard-error output are affected. This issue is fixed in version 4.14.2.
Publish Date: 2026-09-18
URL: CVE-2026-64847
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-09-18
Fix Resolution: 4.14.2
Step up your Open Source Security Game with Mend here