CLEANSTART-2026-ZI93173
Dashboard / Vulnerabilities / CLEANSTART-2026-ZI93173
CLEANSTART-2026-ZI93173
Summary: ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
Details: Multiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-ZI93173.json, https://osv.dev/vulnerability/CVE-2024-53259, https://osv.dev/vulnerability/CVE-2025-47950, https://osv.dev/vulnerability/CVE-2025-58063, https://osv.dev/vulnerability/CVE-2025-59530, https://osv.dev/vulnerability/CVE-2025-64702, https://osv.dev/vulnerability/CVE-2025-68151, https://osv.dev/vulnerability/CVE-2026-26017, https://osv.dev/vulnerability/CVE-2026-26018, https://osv.dev/vulnerability/CVE-2026-32934, https://osv.dev/vulnerability/CVE-2026-32936, https://osv.dev/vulnerability/CVE-2026-33190, https://osv.dev/vulnerability/CVE-2026-33489, https://osv.dev/vulnerability/CVE-2026-33818, https://osv.dev/vulnerability/CVE-2026-35579, https://osv.dev/vulnerability/CVE-2026-39821, https://osv.dev/vulnerability/CVE-2026-39822, https://osv.dev/vulnerability/CVE-2026-40898, https://osv.dev/vulnerability/CVE-2026-42504, https://osv.dev/vulnerability/CVE-2026-42505, https://osv.dev/vulnerability/CVE-2026-46600, https://osv.dev/vulnerability/CVE-2026-56852, https://osv.dev/vulnerability/CVE-2026-56853, https://osv.dev/vulnerability/CVE-2026-56858, https://osv.dev/vulnerability/CVE-2026-56859, https://osv.dev/vulnerability/CVE-2026-56860, https://osv.dev/vulnerability/CVE-2026-56862, https://osv.dev/vulnerability/CVE-2026-56864, https://osv.dev/vulnerability/CVE-2026-56865, https://osv.dev/vulnerability/ghsa-259r-337f-4rfw, https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf, https://nvd.nist.gov/vuln/detail/CVE-2024-53259, https://nvd.nist.gov/vuln/detail/CVE-2025-47950, https://nvd.nist.gov/vuln/detail/CVE-2025-58063, https://nvd.nist.gov/vuln/detail/CVE-2025-59530, https://nvd.nist.gov/vuln/detail/CVE-2025-64702, https://nvd.nist.gov/vuln/detail/CVE-2025-68151, https://nvd.nist.gov/vuln/detail/CVE-2026-26017, https://nvd.nist.gov/vuln/detail/CVE-2026-26018, https://nvd.nist.gov/vuln/detail/CVE-2026-32934, https://nvd.nist.gov/vuln/detail/CVE-2026-32936, https://nvd.nist.gov/vuln/detail/CVE-2026-33190, https://nvd.nist.gov/vuln/detail/CVE-2026-33489, https://nvd.nist.gov/vuln/detail/CVE-2026-33818, https://nvd.nist.gov/vuln/detail/CVE-2026-35579, https://nvd.nist.gov/vuln/detail/CVE-2026-39821, https://nvd.nist.gov/vuln/detail/CVE-2026-39822, https://nvd.nist.gov/vuln/detail/CVE-2026-40898, https://nvd.nist.gov/vuln/detail/CVE-2026-42504, https://nvd.nist.gov/vuln/detail/CVE-2026-42505, https://nvd.nist.gov/vuln/detail/CVE-2026-46600, https://nvd.nist.gov/vuln/detail/CVE-2026-56852, https://nvd.nist.gov/vuln/detail/CVE-2026-56853, https://nvd.nist.gov/vuln/detail/CVE-2026-56858, https://nvd.nist.gov/vuln/detail/CVE-2026-56859, https://nvd.nist.gov/vuln/detail/CVE-2026-56860, https://nvd.nist.gov/vuln/detail/CVE-2026-56862, https://nvd.nist.gov/vuln/detail/CVE-2026-56864, https://nvd.nist.gov/vuln/detail/CVE-2026-56865
Affected packages
Package
Name: kubernetes-dns-node-cache
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
