CVE-2026-3276
Published: June 4, 2026Last modified: August 24, 2026
Description
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | python3 | Fixed (3.11.16-r0) |
| 25 LTS | python3 | Fixed (3.12.14-r0) | |
| Stream | python3 | Fixed (3.14.7-r0) | |
| Hardened Containers | 23 LTS | python3 | Unknown (3.11.3-r0) |
| 25 LTS | python3 | Fixed (3.12.14-r0) | |
| Stream | python3 | Fixed (3.14.7-r0) |
References
- http://www.openwall.com/lists/oss-security/2026/06/03/15
- https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0
- https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598
- https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f
- https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32
- https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066
- https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f
- https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc
- https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c
- https://github.com/python/cpython/issues/149079
- https://github.com/python/cpython/pull/149080
- https://mail.python.org/archives/list/[email protected]/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/