CVE-2026-3276
published 2026-06-03CVE-2026-3276: unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with…
PriorityP338medium6.3CVSS 4.0
AVNACLATPPRNUINVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.49%
39.1th percentile
unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode input containing long runs of combining characters
with alternating Canonical Combining Class values.
This affects all normalization forms.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python3.14 | — | — |
| debian | python3.9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| python | python | — | — |
| python36_3.6 | python36 | — | — |
| python_software_foundation | cpython | < 3.13.14 | 3.13.14 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.6 | 3.14.6 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0b2 | 3.15.0b2 |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| ubuntu | python3.10 | — | — |
| ubuntu | python3.12 | — | — |
| ubuntu | python3.14 | — | — |
CVSS provenance
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.3MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 3.3
CVE-2026-9669 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)
It was discovered that Python's HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)
It was discovered that Python's email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 L
Red Hat
python: Python unicodedata: Denial of Service due to excessive CPU consumption
vendor_redhat·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CWE-606 python: Python unicodedata: Denial of Service due to excessive CPU consumption
python: Python unicodedata: Denial of Service due to excessive CPU consumption
A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 (Exploit Intelligence) - Fix deferred
Package: python3.12 (Red Hat Enterprise Linux 10) - Fix deferred
Package: pytho
GHSA
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values.
ghsa_unreviewed·2026-06-03
CVE-2026-3276 [MEDIUM] CWE-407 unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values.
unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode input containing long runs of combining characters
with alternating Canonical Combining Class values.
This affects all normalization forms.
VulDB
Python CPython Unicode unicodedata.normalize algorithmic complexity
vuldb·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] Python CPython Unicode unicodedata.normalize algorithmic complexity
A vulnerability described as problematic has been identified in Python CPython. Impacted is the function unicodedata.normalize of the component Unicode Handler. The manipulation results in inefficient algorithmic complexity.
This vulnerability is reported as CVE-2026-3276. The attack can be launched remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3276 python3.13: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.13: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.13: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python3.12: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.12: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.12: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 mingw-python3: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 mingw-python3: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 mingw-python3: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python3.6: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.6: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.6: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python3.11: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.11: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.11: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python3.14: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.14: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.14: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python3.10: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.10: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.10: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python3.9: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.9: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.9: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python: Python unicodedata: Denial of Service due to excessive CPU consumption
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python: Python unicodedata: Denial of Service due to excessive CPU consumption
CVE-2026-3276 python: Python unicodedata: Denial of Service due to excessive CPU consumption
unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode input containing long runs of combining characters
with alternating Canonical Combining Class values.
This affects all normalization forms.
Bugzilla
CVE-2026-3276 python3.15: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.15: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
CVE-2026-3276 python3.15: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3276 python3.13: Python unicodedata: Denial of Service due to excessive CPU consumption [epel-all]
bugzilla·2026-06-03·CVSS 6.3
CVE-2026-3276 [MEDIUM] CVE-2026-3276 python3.13: Python unicodedata: Denial of Service due to excessive CPU consumption [epel-all]
CVE-2026-3276 python3.13: Python unicodedata: Denial of Service due to excessive CPU consumption [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26fhttps://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066https://github.com/python/cpython/issues/149079https://github.com/python/cpython/pull/149080https://mail.python.org/archives/list/[email protected]/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/http://www.openwall.com/lists/oss-security/2026/06/03/15
2026-06-03
Published