PT-2026-31812 · Libidn2 · Libidn2

Zou Dikai

·

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-5772

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions versions prior to 2.3
Description A 1-byte stack buffer over-read exists in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT MOST WILDCARD ONLY flag is active. If a wildcard * exhausts the entire hostname string, the function reads one byte past the buffer without a bounds check, potentially causing a crash.
Recommendations Update to version 2.3 or later.

Fix

Buffer Over-read

Weakness Enumeration

Related Identifiers

CVE-2026-5772

Affected Products

Libidn2