The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the "idna"
codec) and the in_table_b2() function of the "stringprep" module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-18 14:16
Updated : 2026-09-10 01:16
NVD link : CVE-2026-17084
Mitre link : CVE-2026-17084
CVE.ORG link : CVE-2026-17084
JSON object : View
Products Affected
No product.
CWE
CWE-436
Interpretation Conflict
