CVE-2026-17084

NONE
CVSS v3
CVSS v2
EPSS (exploit probability)
CWE-436CWE

Description

The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the "idna"
codec) and the in_table_b2() function of the "stringprep" module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references