CVE-2026-17084

Published: Ago 18, 2026 Last Modified: Ago 19, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

The 'stringprep' module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the 'idna'
codec) and the in_table_b2() function of the 'stringprep' module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.

436

Interpretation Conflict

Incomplete
Common Consequences
Security Scopes Affected:
Integrity Other
Potential Impacts:
Unexpected State Varies By Context
Applicable Platforms
All platforms may be affected
View CWE Details
http://www.openwall.com/lists/oss-security/2026/08/18/2
https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3f…
https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547…
https://github.com/python/cpython/issues/155292
https://github.com/python/cpython/pull/155293
https://mail.python.org/archives/list/[email protected]/thread/EUHHT…