CVE-2026-57053

Updated on 23 Jun 2026

Severity

2.5 Low severity

Details

CVSS score
2.5
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Overview

About vulnerability

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

Details

Affected packages:
libidn @ 1.28 (+2 more)

Fixes