CVE-2026-57053: GNU Libidn
Low severity, CVSS 2.5. EPSS: 0.1% chance of exploitation in the next 30 days.
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
Affected products
- GNU Libidn: from 0.1.15, before 1.44 (fixed in 1.44)
Published 2026-06-23. Last modified 2026-06-29.