CVE-2026-57053: GNU Libidn

Low severity, CVSS 2.5. EPSS: 0.1% chance of exploitation in the next 30 days.

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

Affected products

  • GNU Libidn: from 0.1.15, before 1.44 (fixed in 1.44)

Published 2026-06-23. Last modified 2026-06-29.