{"id":"CVE-2026-45409","title":"python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)","summary":"A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding f…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":"CWE-770","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["confidential_cluster_operator","exploit_intelligence","external_secrets_operator_for_red_hat_openshift","migration_toolkit_for_applications 8","migration_toolkit_for_containers","migration_toolkit_for_virtualization","openshift_lightspeed","openshift_service_mesh 3","advanced_cluster_management_for_kubernetes 2","ai_inference_server","ansible_automation_platform 2","ansible_automation_platform_ansible_core 2","build_of_quarkus_native_builder","developer_hub","enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openshift_container_platform 4","openshift_virtualization 4","satellite 6","trusted_artifact_signer","update_infrastructure_4_for_cloud_providers","self_service_automation_portal 2","service_telemetry_framework 1.5","enterprise_linux_baseos_v_10","enterprise_linux_baseos_v_8","enterprise_linux_baseos_v_9","discovery 2","hardened_images","openshift_data_foundation 4.18","update_infrastructure 5"],"patched":["enterprise_linux_baseos_v_10","enterprise_linux_baseos_v_8","enterprise_linux_baseos_v_9","discovery 2","hardened_images","openshift_data_foundation 4.18","update_infrastructure 5"],"published":"2026-06-05","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:23:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-45409"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2485616"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45409"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"url":"https://access.redhat.com/errata/RHSA-2026:54481"},{"url":"https://access.redhat.com/errata/RHSA-2026:54290"},{"url":"https://access.redhat.com/errata/RHSA-2026:54484"},{"url":"https://access.redhat.com/errata/RHSA-2026:61783"},{"url":"https://access.redhat.com/errata/RHSA-2026:25039"},{"url":"https://access.redhat.com/errata/RHSA-2026:25503"},{"url":"https://access.redhat.com/errata/RHSA-2026:34119"},{"url":"https://access.redhat.com/errata/RHSA-2026:56431"},{"url":"https://access.redhat.com/errata/RHSA-2026:66018"},{"url":"https://access.redhat.com/errata/RHSA-2026:58981"},{"url":"https://github.com/kjd/idna"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00408,"epssPercentile":0.34729,"aliases":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:46.288Z","slug":"CVE-2026-45409","body":"## Overview\n\nA flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding function. This could cause the system to consume significant resources, leading to a Denial of Service (DoS), where the affected application becomes unavailable to legitimate users. This issue stems from an incomplete fix for a previously identified vulnerability.\n\n## Vendor advisories\n\n- **RHSA-2026:54481** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54481)\n- **RHSA-2026:54290** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54290)\n- **RHSA-2026:54484** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54484)\n- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)\n- **RHSA-2026:25039** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:25039)\n- **RHSA-2026:25503** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:25503)\n- **RHSA-2026:34119** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34119)\n- **RHSA-2026:56431** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.18 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56431)\n- **RHSA-2026:66018** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66018)\n- **RHSA-2026:58981** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58981)\n- **Red Hat VEX** · Moderate · affected: Confidential Cluster Operator, Exploit Intelligence, External Secrets Operator for Red Hat OpenShift, Migration Toolkit for Applications 8, Migration Toolkit for Containers, Migration Toolkit for Virtualization, … · no fix planned: Confidential Cluster Operator, Exploit Intelligence, External Secrets Operator for Red Hat OpenShift, Migration Toolkit for Applications 8, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json)\n\n**python-idna: idna: Denial of Service via specially crafted long inputs** — rated Moderate by Red Hat. Released 2026-06-05, updated 2026-09-10.\n\nAffected:\n\n- Confidential Cluster Operator\n- Exploit Intelligence\n- External Secrets Operator for Red Hat OpenShift\n- Migration Toolkit for Applications 8\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- OpenShift Lightspeed\n- OpenShift Service Mesh 3\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ansible Automation Platform Ansible Core 2\n- Red Hat build of Quarkus Native builder\n- Red Hat Developer Hub\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n- Red Hat Satellite 6\n- Red Hat Trusted Artifact Signer\n- Red Hat Update Infrastructure 4 for Cloud Providers\n- Self-service automation portal 2\n- Service Telemetry Framework 1.5\n\nFixed:\n\n- Red Hat Enterprise Linux BaseOS (v. 10)\n- Red Hat Enterprise Linux BaseOS (v. 8)\n- Red Hat Enterprise Linux BaseOS (v. 9)\n- Red Hat Discovery 2\n- Red Hat Hardened Images\n- Red Hat Openshift Data Foundation 4.18\n- Red Hat Update Infrastructure 5\n\nNo fix planned:\n\n- Confidential Cluster Operator\n- Exploit Intelligence\n- External Secrets Operator for Red Hat OpenShift\n- Migration Toolkit for Applications 8\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- OpenShift Lightspeed\n- OpenShift Service Mesh 3\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ansible Automation Platform Ansible Core 2\n- Red Hat build of Quarkus Native builder\n- Red Hat Developer Hub\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n- Red Hat Satellite 6\n- Red Hat Trusted Artifact Signer\n- Red Hat Update Infrastructure 4 for Cloud Providers\n- Self-service automation portal 2\n- Service Telemetry Framework 1.5\n\nNot affected:\n\n- Red Hat Discovery 2\n- Red Hat Openshift Data Foundation 4.18\n- Red Hat Update Infrastructure 5\n- Confidential Cluster Operator\n- Confidential Compute Attestation\n- Lightspeed Core\n- Logging Subsystem for Red Hat OpenShift\n- OpenShift Lightspeed\n- OpenShift Service Mesh 3\n- Pen Drive Powered by Red Hat Lightspeed\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54481\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54290\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54484\n\nWorkarounds / mitigations:\n\n- To mitigate this denial-of-service vulnerability, applications utilizing the `idna` Python library should implement input validation to ensure that domain names do not exceed the standard 253-character length limit before being passed to the `idna.encode()` function. This operational control prevents the processing of excessively long inputs that could lead to resource exhaustion and service unavailability.\n\nApplications that pass user-controlled data directly to `idna.encode()` without validat…\n\n## Package advisory (CVE-2026-45409)\n\nAffected packages:\n\n- `idna < 3.15`\n\nPatched in:\n\n- `idna 3.15`\n\nSource: https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}