CVE-2026-45409

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

Beschreibung

Internationale Domainnamen für Anwendungen (IDNA) für Python bietet Unterstützung für Internationale Domainnamen für Anwendungen (IDNA) und Unicode IDNA-Kompatibilitätsverarbeitung. In Versionen vor 3.15 nutzen Payloads wie `"\u0660" * N` oder `"\u30fb" * N + "\u6f22"` die Funktion `valid_contexto`, bevor eine Längenablehnung erfolgt, und bei hohen Werten von `N` wird viel Zeit für die Verarbeitung benötigt. Dies ist das gleiche Problem wie CVE-2024-3651, jedoch war die ursprüngliche Behebung im Jahr 2024 keine vollständige Lösung. Ein speziell gestalteter Argument an die Funktion `idna.encode()` könnte erhebliche Ressourcen verbrauchen und zu einem Denial-of-Service führen. Ab Version 3.14 lehnt die Funktion lange Eingaben so früh wie möglich ab, um den Verbrauch von Ressourcen zu minimieren. In Version 3.15 wurde dieser Ansatz auf weniger genutzte alternative Funktionen (z.B. Umwandlungen pro Label und Codec-Unterstützung) ausgeweitet. Ein Workaround ist verfügbar. Domainnamen dürfen nicht länger als 253 Zeichen sein. Wenn diese Längengrenze vor dem Übergeben des Domains an die `idna.encode()` Funktion durchgesetzt wird, sollte sie keine erheblichen Ressourcen mehr verbrauchen. Dies wird durch willkürlich große Eingaben ausgelöst, die im normalen Gebrauch nicht auftreten würden, aber an die Bibliothek übergeben werden könnten, wenn es keine vorherige Eingabevalidierung durch die höhere Anwendung gibt.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.9
Quelle: nvd-v4
34.3 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 11:15 UTC
CWE-1333

Weakness-Klassen (CWE)

  • CWE-1333Base

    Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Translated2026-07-23 07:10 UTC· nvd@nist.gov
    • Translation: Title: idna de kjd, Description: Nombres de Dominio Internacionalizados en Aplicaciones (IDNA) para Python proporciona soporte para Nombres de Dominio Internacionalizados en Aplicaciones (IDNA) y Procesamiento de Compatibilidad IDNA de Unicode. En versiones anteriores a la 3.15, cargas útiles como '"\u0660" N' o '"\u30fb" N + "\u6f22"' utilizan la función 'valid_contexto' antes del rechazo por longitud, y para valores altos de 'N' tardarán mucho tiempo en procesarse. Este es el mismo problema que CVE-2024-3651, sin embargo, la remediación original en 2024 no fue una solución completa. Un argumento especialmente diseñado para la función 'idna.encode()' podría consumir recursos significativos. Esto puede conducir a una denegación de servicio. A partir de la versión 3.14, la función rechaza entradas largas tan pronto como sea posible antes de cualquier procesamiento adicional para minimizar el consumo de recursos. En la versión 3.15, este enfoque se extendió a funciones alternativas menos utilizadas (es decir, conversiones por etiqueta y soporte de códec). Una solución alternativa está disponible. Los nombres de dominio no pueden exceder los 253 caracteres de longitud. Si se aplica este límite de longitud antes de pasar el dominio a la función 'idna.encode()', ya no debería consumir recursos significativos. Esto se activa por entradas arbitrariamente grandes que no ocurrirían en el uso normal, pero pueden pasarse a la biblioteca asumiendo que no hay validación de entrada preliminar por parte de la aplicación de nivel superior.
  2. Initial Analysis2026-06-15 18:52 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    • CPE Configuration: OR *cpe:2.3:a:kjd:internationalized_domain_names_in_applications:*:*:*:*:*:python:*:* versions up to (excluding) 3.15
    • Reference Type: GitHub, Inc.: https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx Types: Mitigation, Vendor Advisory

Betroffene Betriebssysteme

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

Quellen & Referenzen

Verknüpfte CVEs

93 weitere CVEs anzeigen
IDCVE-2026-45409