Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3276

Опубликовано: 03 июн. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

A flaw was found in the unicodedata.normalize() function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system.

Отчет

Moderate: A flaw in the unicodedata.normalize() function in Python can lead to excessive CPU consumption when processing specially crafted Unicode input. This vulnerability could result in a Denial of Service on systems where applications process untrusted Unicode data using this function, impacting the availability of affected Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2484424python: Python unicodedata: Denial of Service due to excessive CPU consumption

EPSS

Процентиль: 39%
0.00492
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
2 месяца назад

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

nvd
2 месяца назад

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

msrc
2 месяца назад

Potential DoS via quadratic complexity in unicodedata.normalize()

debian
2 месяца назад

unicodedata.normalize() can take excessive CPU time when processing sp ...

github
2 месяца назад

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

EPSS

Процентиль: 39%
0.00492
Низкий

5.3 Medium

CVSS3