← Retour à la recherche de CVE

CVE-2026-3276

Python

Description

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

CVSS 6.3EPSS 0.486%Risque 0.66
Voir la source
Publication
2026-06-03 16:16:29
Versions concernées
unknown
Type
Core software
Dernière modification
2026-08-11 01:17:20
Vecteur
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X