CVE-2026-3276
ADVISORY - nistSummary
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.
EPSS Score: 0.00049 (0.158)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Inefficient Algorithmic Complexity
ADVISORY - redhat
Unchecked Input for Loop Condition
Docker
CREATED
UPDATED
ADVISORY ID
CVE-2026-3276
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| python | dhi | - | - | <3.15.0-beta2 | 3.15.0-beta2 |
| alpine/python-3.10 | apk | alpine | 3.23 | <3.15.0-beta2 | 3.15.0-beta2 |
| alpine/python-3.11 | apk | alpine | 3.23 | <3.15.0-beta2 | 3.15.0-beta2 |
| alpine/python-3.12 | apk | alpine | 3.23 | <3.15.0-beta2 | 3.15.0-beta2 |
| alpine/python-3.13 | apk | alpine | 3.23 | <3.15.0-beta2 | 3.15.0-beta2 |
| alpine/python-3.14 | apk | alpine | 3.23 | <3.15.0-beta2 | 3.15.0-beta2 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
6.3mediumDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-libpython-2026-3276
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
6.3mediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-python-2026-3276
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
6.3mediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-python-min-2026-3276
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
6.3mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-3276
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)