buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2026-3276
Component Overview
Vulnerability Overview
Name
CVE-2026-3276
Source
NVD (
link
)
Debian (
link
)
Description
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.
CWEs
CWE-407
Published Date
Jun 3, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
python3
Patched
Vulnerability Ratings
#
6.3
CVSSv4
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
python3
buildroot
master
3.14.6
Not Affected
python3
openwrt
master
3.14.5-r1
Not Affected
python3
openwrt
openwrt-25.12
3.13.9-r3
Not Affected
python3
yocto
kirkstone
3.10.20
Not Affected
python3
yocto
master
3.14.6
Not Affected
python3
yocto
scarthgap
3.12.13
Not Affected
Resolved with patches
#
python3 (buildroot:2025.02.x)
#
Title
Author
Resolve
1
[3.12] gh-149079: Fix O(n^2) canonical ordering in
Petr Viktorin <encukou@gmail.com>
CVE-2026-3276