CVE-2026-17084
MEDIUM
6,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
The 'stringprep' module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the 'idna'
codec) and the in_table_b2() function of the 'stringprep' module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.
436
Interpretation Conflict
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Other
Potential Impacts:
Unexpected State
Varies By Context
Applicable Platforms
All platforms may be affected
http://www.openwall.com/lists/oss-security/2026/08/18/2
https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3f…
https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547…
https://github.com/python/cpython/issues/155292
https://github.com/python/cpython/pull/155293
https://mail.python.org/archives/list/[email protected]/thread/EUHHT…