CVE-2026-45409: Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as "\u0660" N or "\u30fb" N + "\u6f22" utilize the validcontexto function prior to length rejection, and for high values of N will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the idna.encode() function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the idna.encode() function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.
Other sources
This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. Payloads such as "\u0660" N or "\u30fb" N + "\u6f22" utilize the validcontexto function prior to length rejection, and for high values of N will take a long time to process.
Impact A specially crafted argument to the idna.encode() function could consume significant resources. This may lead to a denial-of-service.
Patches Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support).
Workarounds Domain names cannot exceed 253 characters in length, if this length limit is enforced prior to passing the domain to the idna.encode() function it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/idnato a version that resolves this vulnerability.Fixed in 3.15 - Upgrade
Upgrade
debian/python-idnato a version that resolves this vulnerability.Fixed in 3.10-1+deb13u1Fixed in 3.18-1 - Upgrade
Upgrade
Internationalized Domain Names in Applications (IDNA) for Pythonto a version that resolves this vulnerability.Fixed in 3.14 - Upgrade
Upgrade
Internationalized Domain Names in Applications (IDNA) for Pythonto a version that resolves this vulnerability.Fixed in 3.15 - Configuration
Enforce a maximum domain name length of 253 characters before passing the domain to the `idna.encode()` function to prevent significant resource consumption (workaround described in the material).
Internationalized Domain Names in Applications (IDNA) for Python domain_length_validation = enforce_max_253_characters_before_calling_idna_encode - Compensating control
If the application passes untrusted or arbitrarily large domain inputs to the IDNA library, add/ensure input validation so that domain names are rejected before calling `idna.encode()` when they exceed 253 characters.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45409?
CVE-2026-45409 has a risk rating of 22, indicating a significant vulnerability.
How do I fix CVE-2026-45409?
To fix CVE-2026-45409, ensure that the application correctly implements input validation to reject excessively long payloads.
What software is affected by CVE-2026-45409?
CVE-2026-45409 affects the pip/idna library.
What is the main issue with CVE-2026-45409?
CVE-2026-45409 involves improper input validation that allows for processing excessively long payloads.
How does CVE-2026-45409 relate to CVE-2024-3651?
CVE-2026-45409 is the same issue as CVE-2024-3651, where the original remediation was incomplete.