RHSA-2026:54481: Moderate: python-idna security update
Moderate: python-idna security update
Other sources
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.Security Fix(es): python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-idnato a version that resolves this vulnerability.Fixed in 3.7-6.el10_2 - Upgrade
Upgrade
redhat/python3-idnato a version that resolves this vulnerability.Fixed in 3.7-6.el10_2 - Compensating control
Mitigate CVE-2026-45409 (idna DoS via specially crafted long inputs in python-idna) by rate-limiting requests and/or setting maximum input length limits for data paths that use python-idna.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54481?
The severity of RHSA-2026:54481 is rated as medium with a score of 4.
How do I fix RHSA-2026:54481?
To fix RHSA-2026:54481, update the python-idna package to the latest version provided by your Red Hat repository.
What systems are affected by RHSA-2026:54481?
RHSA-2026:54481 affects various versions of Red Hat Enterprise Linux, including x86_64, ARM 64, and IBM z Systems.
Is RHSA-2026:54481 a critical vulnerability?
No, RHSA-2026:54481 is classified as a moderate vulnerability, not critical.
When was RHSA-2026:54481 published?
RHSA-2026:54481 was published on August 13, 2026.