CVE-2026-3276

ADVISORY - nist

Summary

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

EPSS Score: 0.00475 (0.373)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Inefficient Algorithmic Complexity

ADVISORY - redhat

Unchecked Input for Loop Condition


Docker

CREATED

UPDATED

ADVISORY ID

CVE-2026-3276

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
pythondhi--<3.13.143.13.14
alpine/python-3.10apkalpine3.23<3.13.143.13.14
alpine/python-3.10apkalpine3.23>=3.14.0-alpha1,<3.14.63.14.6
alpine/python-3.10apkalpine3.23>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
alpine/python-3.11apkalpine3.23<3.13.143.13.14
alpine/python-3.11apkalpine3.23>=3.14.0-alpha1,<3.14.63.14.6
alpine/python-3.11apkalpine3.23>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
alpine/python-3.12apkalpine3.23<3.13.143.13.14
alpine/python-3.12apkalpine3.23>=3.14.0-alpha1,<3.14.63.14.6
alpine/python-3.12apkalpine3.23>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
alpine/python-3.13apkalpine3.23<3.13.143.13.14
alpine/python-3.13apkalpine3.23>=3.14.0-alpha1,<3.14.63.14.6
alpine/python-3.13apkalpine3.23>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
alpine/python-3.14apkalpine3.23<3.13.143.13.14
alpine/python-3.14apkalpine3.23>=3.14.0-alpha1,<3.14.63.14.6
alpine/python-3.14apkalpine3.23>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
debian/python-3.10debdebian13<3.13.143.13.14
debian/python-3.10debdebian13>=3.14.0-alpha1,<3.14.63.14.6
debian/python-3.10debdebian13>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
debian/python-3.11debdebian13<3.13.143.13.14
debian/python-3.11debdebian13>=3.14.0-alpha1,<3.14.63.14.6
debian/python-3.11debdebian13>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
debian/python-3.12debdebian13<3.13.143.13.14
debian/python-3.12debdebian13>=3.14.0-alpha1,<3.14.63.14.6
debian/python-3.12debdebian13>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
debian/python-3.13debdebian13<3.13.143.13.14
debian/python-3.13debdebian13>=3.14.0-alpha1,<3.14.63.14.6
debian/python-3.13debdebian13>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
debian/python-3.14debdebian13<3.13.143.13.14
debian/python-3.14debdebian13>=3.14.0-alpha1,<3.14.63.14.6
debian/python-3.14debdebian13>=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2
pythondhi-->=3.14.0-alpha1,<3.14.63.14.6
pythondhi-->=3.15.0-alpha1,<3.15.0-beta23.15.0-beta2

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.3medium

Debian

CREATED

UPDATED

ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Bitnami

CREATED

UPDATED

ADVISORY ID

BIT-libpython-2026-3276

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

6.3medium

Bitnami

CREATED

UPDATED

ADVISORY ID

BIT-python-2026-3276

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

6.3medium

Bitnami

CREATED

UPDATED

ADVISORY ID

BIT-python-min-2026-3276

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

6.3medium

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.3medium

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-94jq-8xf3-wq3h

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-67v5-5v24-jh8c

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-9v2v-xjjc-6jgv

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-hx78-vpm4-v27v

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-jvq7-3xx7-f62p

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-pfv8-h995-8369

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY