← Zurück zur CVE-Suche

CVE-2026-3276

Python

Beschreibung

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

CVSS 6.3EPSS 0.486%Risiko 0.66
Quelle öffnen
Veröffentlicht
2026-06-03 16:16:29
Betroffene Versionen
unknown
Typ
Core software
Zuletzt geändert
2026-08-11 01:17:20
Vektor
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X