PT-2026-41956 · Pypi+3 · Idna+3

·

CVE-2026-45409

·

Published

2026-05-19

·

Updated

2026-08-13

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions idna versions prior to 3.14
Description A specially crafted argument passed to the idna.encode() function can consume significant system resources, potentially leading to a denial-of-service. This occurs because payloads containing specific characters, such as "u0660" * N or "u30fb" * N + "u6f22", utilize the valid contexto() function before length rejection occurs. For high values of N, the processing time increases significantly.
Recommendations Update to version 3.14 or later to ensure long inputs are rejected prior to processing. As a temporary workaround, enforce a domain name length limit of 253 characters before passing the input to the idna.encode() function.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54290
ALSA-2026:54481
ALSA-2026:54484
CLEANSTART-2026-AN24336
CLEANSTART-2026-AZ09261
CLEANSTART-2026-BY15343
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-EN66750
CLEANSTART-2026-FG72002
CLEANSTART-2026-FT24360
CLEANSTART-2026-FU07345
CLEANSTART-2026-FU68971
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-JU43269
CLEANSTART-2026-KE11953
CLEANSTART-2026-KY55512
CLEANSTART-2026-LJ72726
CLEANSTART-2026-NM83456
CLEANSTART-2026-NN42198
CLEANSTART-2026-NR60332
CLEANSTART-2026-QE89118
CLEANSTART-2026-RF67070
CLEANSTART-2026-SA70432
CLEANSTART-2026-SO50412
CLEANSTART-2026-UC45646
CLEANSTART-2026-UO85049
CLEANSTART-2026-WQ85001
CVE-2026-45409
ECHO-B5F1-63A7-4F7C
GHSA-65PC-FJ4G-8RJX
OESA-2026-2605
OPENSUSE-SU-2026:10829-1
OPENSUSE-SU-2026:21048-1
PYSEC-2026-215
RHSA-2026:25039
RHSA-2026:25503
RHSA-2026:26223
RHSA-2026:34119
RHSA-2026:54290
RHSA-2026:54481
RHSA-2026:54484
SUSE-SU-2026:22271-1
SUSE-SU-2026:22356-1
SUSE-SU-2026:2828-1
SUSE-SU-2026:3100-1
SUSE-SU-2026:3101-1
USN-8549-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Idna