PatchSiren

kjd CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kjd CVE published 2026-06-05

CVE-2026-45409

CVE-2026-45409 is a denial-of-service vulnerability affecting Internationalized Domain Names in Applications (IDNA) for Python, specifically versions prior to 3.15. The vulnerability arises from the handling of specially crafted arguments to the `idna.encode()` function, which could consume significant resources. This issue is related to CVE-2024-3651 but was not fully addressed in the previous remediatio [truncated]