VDB

CVE-2026-17084

CVE-2026-17084 PUBLISHED CVSS 6 MEDIUM

Reported by PSF · Published August 18, 2026

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.

Risk Scores

CVSS 4.0
6
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Python Software FoundationCPython0
chainguardpython-3.120, 0, 0
chainguardpython-3.130, 0, 0
chainguardpython-3.140, 0, 0
wolfipython-3.100, 0, 0
wolfipython-3.130, 0, 0
chainguardpython-3.110, 0, 0
chainguardpython-3.100, 0, 0
Python Software FoundationCPython0, 0, 0
wolfipython-3.110, 0, 0
wolfipython-3.140, 0, 0
wolfipython-3.120, 0, 0

Timeline

  • Aug 18, 2026 CVE Published
  • Aug 22, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 5, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 10, 2026 EPSS Score
  • Sep 10, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›