CVE-2026-57053
published 2026-06-23CVE-2026-57053: GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The…
PriorityP410low2.5CVSS 3.1
AVLACHPRLUINSUCNILAN
EPSS
0.15%
4.4th percentile
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | libidn | < 1.44 | 1.44 |
| gnu | libidn | >= 0.1.15 < 1.44 | 1.44 |
| ubuntu | libidn | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU libidn up to 1.43 improper validation of specified quantity in input
vuldb·2026-06-24·CVSS 4.0
CVE-2026-57053 [MEDIUM] GNU libidn up to 1.43 improper validation of specified quantity in input
A vulnerability was found in GNU libidn up to 1.43. It has been rated as problematic. This vulnerability affects unknown code. The manipulation leads to improper validation of specified quantity in input.
This vulnerability is traded as CVE-2026-57053. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal.
ghsa_unreviewed·2026-06-23
CVE-2026-57053 [MEDIUM] CWE-1284 GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal.
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
Ubuntu
Libidn vulnerability
vendor_ubuntu·2026-07-09
CVE-2026-57053 Libidn vulnerability
Title: Libidn vulnerability
Summary: Libidn could be made to crash or expose sensitive information if it
received specially crafted input.
It was discovered that Libidn incorrectly handled certain internationalized
domain name strings. An attacker could possibly use this issue to obtain
sensitive information or cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published