CVE-2026-3276: medium-severity vulnerability in Python Software Foundation CPython
Potential DoS via quadratic complexity in unicodedata.normalize()
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.7%
exploitation probability
0.7%top 48% of all CVEs
observed exploitation
nono source reports it
unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode input containing long runs of combining characters
with alternating Canonical Combining Class values.
This affects all normalization forms.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
Python Software Foundation · CPythonRelated CVEs — Python Software Foundation CPython
In the same product, most dangerous first.
CVE-2024-7592HIGHQuadratic complexity parsing cookies with backslashesEPSS 2.3%CVE-2024-6232HIGHRegular-expression DoS when parsing TarFile headersEPSS 2.2%CVE-2024-12254HIGHUnbounded memory buffering in SelectorSocketTransport.writelines()EPSS 1.9%CVE-2025-13836MEDIUMExcessive read buffering DoS in http.clientEPSS 1.6%CVE-2025-0938MEDIUMURL parser allowed square brackets in domain namesEPSS 1.6%CVE-2025-4517CRITICALArbitrary writes via tarfile realpath overflowEPSS 1.4%
References
https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26fhttps://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1fhttps://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacchttps://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2chttps://github.com/python/cpython/issues/149079https://github.com/python/cpython/pull/149080https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/http://www.openwall.com/lists/oss-security/2026/06/03/15