CLEANSTART-2026-YS01797
Dashboard / Vulnerabilities / CLEANSTART-2026-YS01797
CLEANSTART-2026-YS01797
Summary: ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
Details: Multiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YS01797.json, https://osv.dev/vulnerability/CVE-2026-27145, https://osv.dev/vulnerability/CVE-2026-29181, https://osv.dev/vulnerability/CVE-2026-32280, https://osv.dev/vulnerability/CVE-2026-32281, https://osv.dev/vulnerability/CVE-2026-32282, https://osv.dev/vulnerability/CVE-2026-32283, https://osv.dev/vulnerability/CVE-2026-32288, https://osv.dev/vulnerability/CVE-2026-32289, https://osv.dev/vulnerability/CVE-2026-33186, https://osv.dev/vulnerability/CVE-2026-33810, https://osv.dev/vulnerability/CVE-2026-33811, https://osv.dev/vulnerability/CVE-2026-33814, https://osv.dev/vulnerability/CVE-2026-33818, https://osv.dev/vulnerability/CVE-2026-39820, https://osv.dev/vulnerability/CVE-2026-39821, https://osv.dev/vulnerability/CVE-2026-39823, https://osv.dev/vulnerability/CVE-2026-39825, https://osv.dev/vulnerability/CVE-2026-39826, https://osv.dev/vulnerability/CVE-2026-39827, https://osv.dev/vulnerability/CVE-2026-39828, https://osv.dev/vulnerability/CVE-2026-39829, https://osv.dev/vulnerability/CVE-2026-39830, https://osv.dev/vulnerability/CVE-2026-39831, https://osv.dev/vulnerability/CVE-2026-39832, https://osv.dev/vulnerability/CVE-2026-39833, https://osv.dev/vulnerability/CVE-2026-39834, https://osv.dev/vulnerability/CVE-2026-39835, https://osv.dev/vulnerability/CVE-2026-39836, https://osv.dev/vulnerability/CVE-2026-39883, https://osv.dev/vulnerability/CVE-2026-41178, https://osv.dev/vulnerability/CVE-2026-42499, https://osv.dev/vulnerability/CVE-2026-42504, https://osv.dev/vulnerability/CVE-2026-42507, https://osv.dev/vulnerability/CVE-2026-42508, https://osv.dev/vulnerability/CVE-2026-46595, https://osv.dev/vulnerability/CVE-2026-46597, https://osv.dev/vulnerability/CVE-2026-46598, https://osv.dev/vulnerability/CVE-2026-46600, https://osv.dev/vulnerability/CVE-2026-56853, https://osv.dev/vulnerability/CVE-2026-56858, https://osv.dev/vulnerability/CVE-2026-56859, https://osv.dev/vulnerability/CVE-2026-56860, https://osv.dev/vulnerability/CVE-2026-56862, https://osv.dev/vulnerability/CVE-2026-73500, https://osv.dev/vulnerability/ghsa-259r-337f-4rfw, https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g, https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf, https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3, https://nvd.nist.gov/vuln/detail/CVE-2026-27145, https://nvd.nist.gov/vuln/detail/CVE-2026-29181, https://nvd.nist.gov/vuln/detail/CVE-2026-32280, https://nvd.nist.gov/vuln/detail/CVE-2026-32281, https://nvd.nist.gov/vuln/detail/CVE-2026-32282, https://nvd.nist.gov/vuln/detail/CVE-2026-32283, https://nvd.nist.gov/vuln/detail/CVE-2026-32288, https://nvd.nist.gov/vuln/detail/CVE-2026-32289, https://nvd.nist.gov/vuln/detail/CVE-2026-33186, https://nvd.nist.gov/vuln/detail/CVE-2026-33810, https://nvd.nist.gov/vuln/detail/CVE-2026-33811, https://nvd.nist.gov/vuln/detail/CVE-2026-33814, https://nvd.nist.gov/vuln/detail/CVE-2026-33818, https://nvd.nist.gov/vuln/detail/CVE-2026-39820, https://nvd.nist.gov/vuln/detail/CVE-2026-39821, https://nvd.nist.gov/vuln/detail/CVE-2026-39823, https://nvd.nist.gov/vuln/detail/CVE-2026-39825, https://nvd.nist.gov/vuln/detail/CVE-2026-39826, https://nvd.nist.gov/vuln/detail/CVE-2026-39827, https://nvd.nist.gov/vuln/detail/CVE-2026-39828, https://nvd.nist.gov/vuln/detail/CVE-2026-39829, https://nvd.nist.gov/vuln/detail/CVE-2026-39830, https://nvd.nist.gov/vuln/detail/CVE-2026-39831, https://nvd.nist.gov/vuln/detail/CVE-2026-39832, https://nvd.nist.gov/vuln/detail/CVE-2026-39833, https://nvd.nist.gov/vuln/detail/CVE-2026-39834, https://nvd.nist.gov/vuln/detail/CVE-2026-39835, https://nvd.nist.gov/vuln/detail/CVE-2026-39836, https://nvd.nist.gov/vuln/detail/CVE-2026-39883, https://nvd.nist.gov/vuln/detail/CVE-2026-41178, https://nvd.nist.gov/vuln/detail/CVE-2026-42499, https://nvd.nist.gov/vuln/detail/CVE-2026-42504, https://nvd.nist.gov/vuln/detail/CVE-2026-42507, https://nvd.nist.gov/vuln/detail/CVE-2026-42508, https://nvd.nist.gov/vuln/detail/CVE-2026-46595, https://nvd.nist.gov/vuln/detail/CVE-2026-46597, https://nvd.nist.gov/vuln/detail/CVE-2026-46598, https://nvd.nist.gov/vuln/detail/CVE-2026-46600, https://nvd.nist.gov/vuln/detail/CVE-2026-56853, https://nvd.nist.gov/vuln/detail/CVE-2026-56858, https://nvd.nist.gov/vuln/detail/CVE-2026-56859, https://nvd.nist.gov/vuln/detail/CVE-2026-56860, https://nvd.nist.gov/vuln/detail/CVE-2026-56862, https://nvd.nist.gov/vuln/detail/CVE-2026-73500
Affected packages
Package
Name: calico
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
