CVE-2026-19445 - Use-after-free of a server-side SSLContext when sni_callback switches contexts
CVE ID :CVE-2026-19445 Published : Sept. 30, 2026, 5:16 p.m. | 1 hour, 22 minutes ago Description :A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a...