MEDIUM 6.0 NVD
CVE-2026-17084
The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the
The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the "idna"
codec) and the in_table_b2() function of the "stringprep" module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.
References
- https://github.com/python/cpython/issues/155292
- https://github.com/python/cpython/pull/155293
- https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUH
- https://www.openwall.com/lists/oss-security/2026/08/18/2
This medium severity vulnerability with a CVSS score of 6.0 was published on 2026-08-18 via NVD.
vulnfeed aggregates 11140 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.