CVE-2026-17084

NameCVE-2026-17084
DescriptionThe "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1147445

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pypy3 (PTS)bookworm7.3.11+dfsg-2+deb12u3vulnerable
trixie7.3.19+dfsg-2vulnerable
forky, sid8.0.0+dfsg-1vulnerable
python3.11 (PTS)bookworm3.11.2-6+deb12u8vulnerable
bookworm (security)3.11.2-6+deb12u3vulnerable
python3.13 (PTS)trixie3.13.5-2+deb13u5vulnerable
forky, sid3.13.15-1vulnerable
python3.14 (PTS)forky3.14.7-4fixed
sid3.14.7-5fixed
python3.15 (PTS)forky3.15.0~rc2-2fixed
sid3.15.0~rc2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pypy3source(unstable)(unfixed)1147445
python2.7sourcebullseye(unfixed)end-of-life
python2.7source(unstable)(unfixed)
python3.11source(unstable)(unfixed)
python3.13source(unstable)(unfixed)
python3.14source(unstable)3.14.7-3
python3.15source(unstable)3.15.0~rc2-1
python3.9source(unstable)(unfixed)

Notes

[trixie] - python3.13 <no-dsa> (Minor issue)
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue)
https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/
https://github.com/python/cpython/issues/155292
https://github.com/python/cpython/pull/155293
Fixed by: https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc (main)
Fixed by: https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7 (v3.15.0rc2)
Fixed by: https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae (3.14)

Search for package or bug name: Reporting problems