unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.
CVE-2026-3276
This medium-severity CVE scores 6.3 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.5%, top 61% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
A fix is available — apply it.
- CVSS v3
- 6.3
- EG Score
- 6.3(medium)
- EPSS
- 39.3%
- KEV
- Not listed
Published
June 3, 2026
Last Modified
July 22, 2026
Advisory Details (8)
Auto-updated Jun 13, 2026oss-security - [CVE-2026-3276] Potential DoS via quadratic complexity in unicodedata.normalize()
http://www.openwall.com/lists/oss-security/2026/06/03/15Mailman 3 [CVE-2026-3276] Potential DoS via quadratic complexity in unicodedata.normalize() - Security-announce - python.org
https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/gh-149079: Fix O(n^2) canonical ordering in unicodedata.normalize()
Fix merged in python/cpython PR #149080 on 2026-06-02 — awaiting tagged release
https://github.com/python/cpython/pull/149080commit c5512bd7c1dc (python/cpython)
Fix landed in python/cpython commit c5512bd7c1dc — awaiting tagged release
https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066commit ba785b88add9 (python/cpython)
Fix landed in python/cpython commit ba785b88add9 — awaiting tagged release
https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32commit 991224b1e831 (python/cpython)
Fix landed in python/cpython commit 991224b1e831 — awaiting tagged release
https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26fcommit 6b505d1f41f8 (python/cpython)
Fix landed in python/cpython commit 6b505d1f41f8 — awaiting tagged release
https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0Vendor Advisories for CVE-2026-3276(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(1)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | python3.12-venv (3.12.3-1ubuntu0.15) @ noble | 2026-07-16 | ubuntu |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(1)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Data Freshness Timeline
(refreshed 9× in last 7d / 53× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 02:29 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 17:03 UTCEPSS rescore
- 2026-07-16 00:38 UTCVendor advisory
- 2026-07-16 00:38 UTCGHSA enrichment
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 02:00 UTCEPSS rescore
- 2026-07-14 03:30 UTCVendor advisory
- 2026-07-14 03:30 UTCGHSA enrichment
- 2026-07-13 22:30 UTCEPSS rescore
- 2026-07-13 06:13 UTCEPSS rescore
- 2026-07-13 06:13 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-11 12:43 UTCVendor advisory
- 2026-07-11 12:43 UTCGHSA enrichment
- 2026-07-11 08:27 UTCEPSS rescore
- 2026-07-09 19:10 UTCEPSS rescore
- 2026-07-08 16:26 UTCVendor advisory
- 2026-07-08 16:26 UTCGHSA enrichment
- 2026-07-08 15:15 UTCEPSS rescore
Show 74 moreShow fewer
- 2026-07-07 13:46 UTCEPSS rescore
- 2026-07-06 16:27 UTCEPSS rescore
- 2026-07-06 16:27 UTCEPSS rescore
- 2026-07-06 02:23 UTCEPSS rescore
- 2026-07-06 02:23 UTCEPSS rescore
- 2026-07-05 02:30 UTCEPSS rescore
- 2026-07-04 06:31 UTCEPSS rescore
- 2026-07-03 23:37 UTCGHSA enrichment
- 2026-07-02 23:25 UTCGHSA enrichment
- 2026-07-01 23:22 UTCGHSA enrichment
- 2026-07-01 15:06 UTCEPSS rescore
- 2026-06-30 23:22 UTCEPSS rescore
- 2026-06-30 23:14 UTCGHSA enrichment
- 2026-06-29 23:11 UTCGHSA enrichment
- 2026-06-29 14:06 UTCEPSS rescore
- 2026-06-28 23:00 UTCGHSA enrichment
- 2026-06-28 14:07 UTCEPSS rescore
- 2026-06-28 04:56 UTCEPSS rescore
- 2026-06-27 22:58 UTCGHSA enrichment
- 2026-06-27 03:08 UTCEPSS rescore
- 2026-06-26 22:56 UTCGHSA enrichment
- 2026-06-25 22:35 UTCGHSA enrichment
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-24 22:22 UTCGHSA enrichment
- 2026-06-24 14:05 UTCEPSS rescore
- 2026-06-23 21:33 UTCEPSS rescore
- 2026-06-23 19:07 UTCGHSA enrichment
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-19 23:52 UTCGHSA enrichment
- 2026-06-19 19:25 UTCEPSS rescore
- 2026-06-18 21:33 UTCGHSA enrichment
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-17 19:10 UTCGHSA enrichment
- 2026-06-17 17:53 UTCEPSS rescore
- 2026-06-16 19:08 UTCGHSA enrichment
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 19:03 UTCGHSA enrichment
- 2026-06-15 17:49 UTCEPSS rescore
- 2026-06-14 23:18 UTCEPSS rescore
- 2026-06-14 18:45 UTCGHSA enrichment
- 2026-06-13 23:00 UTCEPSS rescore
- 2026-06-13 18:44 UTCGHSA enrichment
- 2026-06-12 23:12 UTCEPSS rescore
- 2026-06-12 23:12 UTCEPSS rescore
- 2026-06-12 18:12 UTCGHSA enrichment
- 2026-06-11 18:10 UTCGHSA enrichment
- 2026-06-11 14:00 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 18:09 UTCGHSA enrichment
- 2026-06-10 13:22 UTCEPSS rescore
- 2026-06-09 18:07 UTCGHSA enrichment
- 2026-06-08 18:06 UTCGHSA enrichment
- 2026-06-08 14:17 UTCEPSS rescore
- 2026-06-08 14:17 UTCEPSS rescore
- 2026-06-07 15:54 UTCGHSA enrichment
- 2026-06-07 15:25 UTCEPSS rescore
- 2026-06-07 15:25 UTCEPSS rescore
- 2026-06-07 15:25 UTCEPSS rescore
- 2026-06-06 15:53 UTCGHSA enrichment
- 2026-06-06 13:47 UTCEPSS rescore
- 2026-06-06 13:47 UTCEPSS rescore
- 2026-06-05 22:47 UTCEPSS rescore
- 2026-06-05 22:47 UTCEPSS rescore
- 2026-06-05 15:52 UTCGHSA enrichment
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-04 15:51 UTCGHSA enrichment
- 2026-06-03 15:50 UTCEG score recompute
Frequently asked(5)
What is CVE-2026-3276?
When was CVE-2026-3276 disclosed?
Is CVE-2026-3276 actively exploited?
What is the CVSS score of CVE-2026-3276?
How do I remediate CVE-2026-3276?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-3276
Is Your Infrastructure Affected by CVE-2026-3276?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.