CVE-2026-57053: Medium severity GNU libidn vulnerability
Published Jun 23, 2026
·Updated
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idnatounicodeinternal. The affected code is not present in libidn2.
Affected Software
3 affected componentsFixes available
GNU libidn<1.44
GNU libidn>=0.1.15<1.44
debian/libidn<=1.33-3, <=1.41-1, <=1.43-1
1.44-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libidnto a version that resolves this vulnerability.Fixed in 1.44-1 - Upgrade
Upgrade
GNU libidnto a version that resolves this vulnerability.Fixed in 1.44
Event History
Jun 23, 2026
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeaknessAffected Software
Jul 9, 2026
Data Sourced
via Debian·03:51 PM
DescriptionAffected Software
Data Sourced
via Launchpad·03:52 PM
Description
Jul 10, 2026
Data Sourced
via Ubuntu·03:52 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57053?
CVE-2026-57053 has a medium severity rating of 4.
2
How do I fix CVE-2026-57053?
To mitigate CVE-2026-57053, upgrade your GNU libidn to version 1.44 or later.
3
What kind of vulnerability is CVE-2026-57053?
CVE-2026-57053 is an out-of-bounds read vulnerability affecting ToUnicode APIs.
4
Which versions of GNU libidn are affected by CVE-2026-57053?
GNU libidn versions prior to 1.44 are affected by CVE-2026-57053.
5
Is libidn2 affected by CVE-2026-57053?
No, the affected code is not present in libidn2.