CVE-2026-3276
ADVISORY - nistSummary
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.
EPSS Score: 0.00492 (0.384)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Inefficient Algorithmic Complexity
ADVISORY - redhat
Unchecked Input for Loop Condition
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in