#VU120191 Input validation error in idna - CVE-2024-12224
Published: December 18, 2025
idna
Rust Team
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to an error within the UTS 46 specification when handling Punycode labels that do not produce any non-ASCII output. A remote attacker can construct a specially crafted hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.