← Vulnerability feed

Vulnerability record · CVE-2026-57053 · published 23 June 2026

CVE-2026-57053: Gnu libidn vulnerability

Gnu · Libidn

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

2.5 CVSS 3.1 Low EPSS 0.14% · top 97.3% CWE-1284 · CWE-1284
2.5CVSS 3.1 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
29 Jun 2026Last modified by NVD

Description

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-57053 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2016-6263Gnu libidn out-of-bounds read vulnerabilityThe stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-…EPSS 3.9%7.5CVE-2016-6262Gnu libidn out-of-bounds read vulnerabilityidn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-…EPSS 6.5%7.5CVE-2016-6261Opensuse leap out-of-bounds read vulnerabilityThe idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read…EPSS 3.9%7.5CVE-2015-8948Opensuse leap out-of-bounds read vulnerabilityidn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an …EPSS 6.7%7.5CVE-2015-2059Gnu libidn memory buffer overflow vulnerabilityThe stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly…EPSS 3.2%7.8CVE-2010-3904Linux Kernel RDS rds_page_copy_user Improper Input Validation Privilege EscalationThe rds_page_copy_user function in net/rds/page.c in the Linux kernel before 2.6.36 fails to properly validate addresses obtained from user space. A …KEVEPSS 14%analysed9.8CVE-2022-20699Cisco Small Business RV Series Routers Stack Buffer OverflowCisco Small Business RV160, RV260, RV340 and RV345 series routers contain a stack-based buffer overflow (CWE-121) that can be triggered remotely with…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2026-57053), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.