Tech & AI News
Hacker News

When str.lower() is a security vulnerability in Python – Seth Larson

Python’s IDNA 2003 implementation used `str.lower()` for the StringPrep case-folding step, but the algorithm requires Unicode 3.2.0 rules; newer Unicode versions produce different encodings (e.g., “ᎠᎠ”.encode("idna") yields `xn--58da` versus `xn--kz9aa`). The vulnerability was fixed by adding exception mappings that force `str.lower()` to emulate Unicode 3.2.0 behavior, aligning IDNA 2003 with its specification (CVE-2026-17084).