unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade python3 | Aug 17, 2026 | Jun 3, 2026 |
| Amazon_linux_2023 | — | Upgrade python3-develUpgrade python3.11-tkinterUpgrade python3.14-libsUpgrade python3.14-freethreading-libsUpgrade python3-idleUpgrade python-unversioned-commandUpgrade python3Upgrade python3.14-debuginfoUpgrade python3.9-debugsourceUpgrade python3.14-testUpgrade python3.14-freethreading-develUpgrade python3.14-freethreading-testUpgrade python3.11-testUpgrade python3.14Upgrade python3.9-debuginfoUpgrade python3.11-debugUpgrade python3.14-freethreadingUpgrade python3-tkinterUpgrade python3.11Upgrade python3.11-debugsourceUpgrade python3.14-idleUpgrade python3.14-debugsourceUpgrade python3.11-develUpgrade python3.11-idleUpgrade python3.11-debuginfoUpgrade python3-debugUpgrade python3-testUpgrade python3.14-tkinterUpgrade python3-libsUpgrade python3.14-freethreading-tkinterUpgrade python3.11-libsUpgrade python3.14-develUpgrade python3.14-debugUpgrade python3.14-freethreading-debugUpgrade python3.14-freethreading-idle | Jul 8, 2026 | Jun 3, 2026 |
| Debian | — | Upgrade python3.13 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 3, 2026 |
| Ubuntu | — | Upgrade libpython3.12t64Upgrade python3.14Upgrade libpython3.10Upgrade python3.10Upgrade libpython3.14Upgrade python3.12 | Jul 6, 2026 | Jun 3, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub