---
id: CVE-2026-45409
title: >-
  python-idna: idna: Denial of Service via specially crafted long inputs
  (CVE-2026-45409)
summary: >-
  A flaw was found in the idna library, which handles Internationalized Domain
  Names in Python applications. A remote attacker could exploit this
  vulnerability by sending specially crafted, excessively long inputs to the
  library's encoding f…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - confidential_cluster_operator
  - exploit_intelligence
  - external_secrets_operator_for_red_hat_openshift
  - migration_toolkit_for_applications 8
  - migration_toolkit_for_containers
  - migration_toolkit_for_virtualization
  - openshift_lightspeed
  - openshift_service_mesh 3
  - advanced_cluster_management_for_kubernetes 2
  - ai_inference_server
  - ansible_automation_platform 2
  - ansible_automation_platform_ansible_core 2
  - build_of_quarkus_native_builder
  - developer_hub
  - enterprise_linux 10
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_virtualization 4
  - satellite 6
  - trusted_artifact_signer
  - update_infrastructure_4_for_cloud_providers
  - self_service_automation_portal 2
  - service_telemetry_framework 1.5
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_v_9
  - discovery 2
  - hardened_images
  - openshift_data_foundation 4.18
  - update_infrastructure 5
patched:
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_v_9
  - discovery 2
  - hardened_images
  - openshift_data_foundation 4.18
  - update_infrastructure 5
published: '2026-06-05'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T17:23:38+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-45409'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2485616'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-45409'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45409'
  - url: 'https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54481'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54290'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54484'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61783'
  - url: 'https://access.redhat.com/errata/RHSA-2026:25039'
  - url: 'https://access.redhat.com/errata/RHSA-2026:25503'
  - url: 'https://access.redhat.com/errata/RHSA-2026:34119'
  - url: 'https://access.redhat.com/errata/RHSA-2026:56431'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66018'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
  - url: 'https://github.com/kjd/idna'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00408
epssPercentile: 0.34826
aliases:
  - GHSA-65pc-fj4g-8rjx
  - PYSEC-2026-215
ecosystem: pip
ingestedAt: '2026-07-08T18:25:46.288Z'
---

## Overview

A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding function. This could cause the system to consume significant resources, leading to a Denial of Service (DoS), where the affected application becomes unavailable to legitimate users. This issue stems from an incomplete fix for a previously identified vulnerability.

## Vendor advisories

- **RHSA-2026:54481** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54481)
- **RHSA-2026:54290** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54290)
- **RHSA-2026:54484** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54484)
- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)
- **RHSA-2026:25039** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:25039)
- **RHSA-2026:25503** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:25503)
- **RHSA-2026:34119** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34119)
- **RHSA-2026:56431** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.18 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56431)
- **RHSA-2026:66018** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66018)
- **RHSA-2026:58981** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58981)
- **Red Hat VEX** · Moderate · affected: Confidential Cluster Operator, Exploit Intelligence, External Secrets Operator for Red Hat OpenShift, Migration Toolkit for Applications 8, Migration Toolkit for Containers, Migration Toolkit for Virtualization, … · no fix planned: Confidential Cluster Operator, Exploit Intelligence, External Secrets Operator for Red Hat OpenShift, Migration Toolkit for Applications 8, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json)

**python-idna: idna: Denial of Service via specially crafted long inputs** — rated Moderate by Red Hat. Released 2026-06-05, updated 2026-09-10.

Affected:

- Confidential Cluster Operator
- Exploit Intelligence
- External Secrets Operator for Red Hat OpenShift
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- OpenShift Lightspeed
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ansible Automation Platform Ansible Core 2
- Red Hat build of Quarkus Native builder
- Red Hat Developer Hub
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 4
- Red Hat Satellite 6
- Red Hat Trusted Artifact Signer
- Red Hat Update Infrastructure 4 for Cloud Providers
- Self-service automation portal 2
- Service Telemetry Framework 1.5

Fixed:

- Red Hat Enterprise Linux BaseOS (v. 10)
- Red Hat Enterprise Linux BaseOS (v. 8)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Discovery 2
- Red Hat Hardened Images
- Red Hat Openshift Data Foundation 4.18
- Red Hat Update Infrastructure 5

No fix planned:

- Confidential Cluster Operator
- Exploit Intelligence
- External Secrets Operator for Red Hat OpenShift
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- OpenShift Lightspeed
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ansible Automation Platform Ansible Core 2
- Red Hat build of Quarkus Native builder
- Red Hat Developer Hub
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 4
- Red Hat Satellite 6
- Red Hat Trusted Artifact Signer
- Red Hat Update Infrastructure 4 for Cloud Providers
- Self-service automation portal 2
- Service Telemetry Framework 1.5

Not affected:

- Red Hat Discovery 2
- Red Hat Openshift Data Foundation 4.18
- Red Hat Update Infrastructure 5
- Confidential Cluster Operator
- Confidential Compute Attestation
- Lightspeed Core
- Logging Subsystem for Red Hat OpenShift
- OpenShift Lightspeed
- OpenShift Service Mesh 3
- Pen Drive Powered by Red Hat Lightspeed

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54481
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54290
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54484

Workarounds / mitigations:

- To mitigate this denial-of-service vulnerability, applications utilizing the `idna` Python library should implement input validation to ensure that domain names do not exceed the standard 253-character length limit before being passed to the `idna.encode()` function. This operational control prevents the processing of excessively long inputs that could lead to resource exhaustion and service unavailability.

Applications that pass user-controlled data directly to `idna.encode()` without validat…

## Package advisory (CVE-2026-45409)

Affected packages:

- `idna < 3.15`

Patched in:

- `idna 3.15`

Source: https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx
