Commit Graph

1 Commits

Author SHA1 Message Date
RHEL Packaging Agent
2005a8a7b5 Fix CVE-2026-45409: quadratic time complexity in IDNA validation
Backport two upstream commits (c0dda45, e1cb465) fixing
CVE-2026-45409 (GHSA-65pc-fj4g-8rjx). The patch adds early
length checks in encode(), decode(), and check_label() in
idna/core.py to reject oversized inputs before per-label
validation runs, preventing CONTEXTO/CONTEXTJ-heavy inputs
from driving validation into quadratic time complexity.

CVE: CVE-2026-45409
Upstream patches:
 - c0dda4501d.patch
 - e1cb465b63.patch
Resolves: RHEL-215651

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
Co-authored-by: Tomáš Hrnčiar <thrnciar@redhat.com>
2026-08-10 10:46:24 +02:00