CVE-2026-3276: falha de média gravidade em Python Software Foundation CPython
Potential DoS via quadratic complexity in unicodedata.normalize()
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.3epss 0.7%
probabilidade de exploração
0.7%top 48% das CVEs
exploração observada
nãonenhuma fonte reporta
unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode input containing long runs of combining characters
with alternating Canonical Combining Class values.
This affects all normalization forms.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Produtos afetados
Python Software Foundation · CPythonCVEs relacionadas — Python Software Foundation CPython
No mesmo produto, das mais perigosas para as menos.
CVE-2024-7592HIGHQuadratic complexity parsing cookies with backslashesEPSS 2.3%CVE-2024-6232HIGHRegular-expression DoS when parsing TarFile headersEPSS 2.2%CVE-2024-12254HIGHUnbounded memory buffering in SelectorSocketTransport.writelines()EPSS 1.9%CVE-2025-13836MEDIUMExcessive read buffering DoS in http.clientEPSS 1.6%CVE-2025-0938MEDIUMURL parser allowed square brackets in domain namesEPSS 1.6%CVE-2025-4517CRITICALArbitrary writes via tarfile realpath overflowEPSS 1.4%
Referências
https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26fhttps://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1fhttps://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacchttps://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2chttps://github.com/python/cpython/issues/149079https://github.com/python/cpython/pull/149080https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/http://www.openwall.com/lists/oss-security/2026/06/03/15