Skip to content

anyio-4.6.0-py3-none-any.whl: 3 vulnerabilities (highest severity is: 9.1) #461

Description

@mend-bolt-for-github
Vulnerable Library - anyio-4.6.0-py3-none-any.whl

High level compatibility layer for multiple asynchronous event loop implementations

Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl

Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (anyio version) Remediation Possible**
CVE-2026-63374 Critical 9.1 anyio-4.6.0-py3-none-any.whl Direct 4.14.2 ❌
CVE-2026-63349 Medium 5.7 anyio-4.6.0-py3-none-any.whl Direct 4.14.2 ❌
CVE-2026-64847 Medium 5.5 anyio-4.6.0-py3-none-any.whl Direct 4.14.2 ❌

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-63374

Vulnerable Library - anyio-4.6.0-py3-none-any.whl

High level compatibility layer for multiple asynchronous event loop implementations

Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl

Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Dependency Hierarchy:

  • ❌ anyio-4.6.0-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a non-ASCII domain is hijacked or redirected, an attacker can obtain a legitimate certificate for the different ASCII hostname produced by IDNA 2003 and present it to the client, causing the malicious endpoint's certificate to validate. This issue is fixed in version 4.14.2.

Publish Date: 2026-09-22

URL: CVE-2026-63374

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-09-18

Fix Resolution: 4.14.2

Step up your Open Source Security Game with Mend here

CVE-2026-63349

Vulnerable Library - anyio-4.6.0-py3-none-any.whl

High level compatibility layer for multiple asynchronous event loop implementations

Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl

Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Dependency Hierarchy:

  • ❌ anyio-4.6.0-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in version 4.14.2.

Publish Date: 2026-09-18

URL: CVE-2026-63349

CVSS 3 Score Details (5.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: High
    • Privileges Required: High
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-09-18

Fix Resolution: 4.14.2

Step up your Open Source Security Game with Mend here

CVE-2026-64847

Vulnerable Library - anyio-4.6.0-py3-none-any.whl

High level compatibility layer for multiple asynchronous event loop implementations

Library home page: https://files.pythonhosted.org/packages/9e/ef/7a4f225581a0d7886ea28359179cb861d7fbcdefad29663fc1167b86f69f/anyio-4.6.0-py3-none-any.whl

Sample Path to Dependency File: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Path to vulnerable library: /assessment_module_manager/.ws-temp-IVRDMW-requirements.txt

Dependency Hierarchy:

  • ❌ anyio-4.6.0-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 2c2e4a13b710ceb8f65cd32664895e4278834389

Found in base branch: develop

Vulnerability Details

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains, even though the documented behavior redirects all three standard streams. Worker code that writes enough attacker-influenced data to sys.stderr can fill the pipe and block before returning the standard-output protocol response, causing the awaiting process-pool call to remain blocked indefinitely. Applications that run untrusted or faulty worker code capable of producing substantial standard-error output are affected. This issue is fixed in version 4.14.2.

Publish Date: 2026-09-18

URL: CVE-2026-64847

CVSS 3 Score Details (5.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-09-18

Fix Resolution: 4.14.2

Step up your Open Source Security Game with Mend here

Activity

  1. changed the title [-]anyio-4.6.0-py3-none-any.whl: 2 vulnerabilities (highest severity is: 9.1)[/-] [+]anyio-4.6.0-py3-none-any.whl: 3 vulnerabilities (highest severity is: 9.1)[/+] on Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions