CVE-2026-17084

Published: August 20, 2026Last modified: October 3, 2026

Description

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpython3Fixed (3.11.17-r0)
25 LTSpython3Fixed (3.12.15-r0)
Streampython3Fixed (3.14.8-r3)
Hardened Containers23 LTSpython3Fixed (3.11.17-r0)
25 LTSpython3Fixed (3.12.15-r0)
Streampython3Unknown (3.11.4-r0)

References

ON THIS PAGE