new file mode 100644
@@ -0,0 +1,75 @@
+From 6c647e3d5d9daca452ae74fc10d50f20e998e444 Mon Sep 17 00:00:00 2001
+From: Kim Davies <kim@cynosure.com.au>
+Date: Sun, 10 May 2026 08:47:22 -0700
+Subject: [PATCH] Merge commit from fork
+
+CVE: CVE-2026-45409
+Upstream-Status: Backport [https://github.com/kjd/idna/commit/c0dda4501df5d91c3181ce6f962dc5de74e82cc1]
+
+Backport Changes:
+- Omitted HISTORY.rst because its 3.14 release entry conflicts with the 3.11
+ history and is not required for the security fix.
+
+(cherry picked from commit c0dda4501df5d91c3181ce6f962dc5de74e82cc1)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ idna/core.py | 14 ++++++++++++++
+ tests/test_idna.py | 13 +++++++++++++
+ 2 files changed, 27 insertions(+)
+
+diff --git a/idna/core.py b/idna/core.py
+index 8177bf7..ce995c9 100644
+--- a/idna/core.py
++++ b/idna/core.py
+@@ -377,6 +377,15 @@ def encode(
+ raise IDNAError("should pass a unicode string to the function rather than a byte string.")
+ if uts46:
+ s = uts46_remap(s, std3_rules, transitional)
++
++ # Reject inputs that exceed the maximum DNS domain length up-front.
++ # Each codepoint in a U-label contributes at least one octet to its
++ # A-label form, so any input longer than the domain limit cannot
++ # produce a valid A-domain. Short-circuiting here prevents per-label
++ # validation from being driven into quadratic time
++ if len(s) > 254:
++ raise IDNAError("Domain too long")
++
+ trailing_dot = False
+ result = []
+ if strict:
+@@ -415,6 +424,11 @@ def decode(
+ raise IDNAError("Invalid ASCII in A-label")
+ if uts46:
+ s = uts46_remap(s, std3_rules, False)
++ # See encode() for rationale; the same bound applies because every
++ # legal A-domain is at most 254 octets and every codepoint of a
++ # legal U-domain contributes at least one octet to its A-form.
++ if len(s) > 254:
++ raise IDNAError("Domain too long")
+ trailing_dot = False
+ result = []
+ if not strict:
+diff --git a/tests/test_idna.py b/tests/test_idna.py
+index b59f5e5..ff24ebf 100755
+--- a/tests/test_idna.py
++++ b/tests/test_idna.py
+@@ -80,6 +80,19 @@ class IDNATests(unittest.TestCase):
+ self.assertFalse(idna.valid_label_length("a" * 64))
+ self.assertRaises(idna.IDNAError, idna.encode, "a" * 64)
+
++ def test_oversized_input_rejected_promptly(self):
++ # GHSA-65pc-fj4g-8rjx: encode/decode must reject inputs that
++ # exceed the maximum DNS domain length before per-codepoint
++ # validation runs, so labels dominated by CONTEXTO codepoints
++ # cannot drive validation into quadratic time.
++ import time
++
++ for payload in ("٠" * 8000, "・" * 8000 + "漢"):
++ start = time.perf_counter()
++ self.assertRaises(idna.IDNAError, idna.encode, payload)
++ self.assertRaises(idna.IDNAError, idna.decode, payload)
++ self.assertLess(time.perf_counter() - start, 1.0)
++
+ def test_check_bidi(self):
+ la = "\u0061"
+ r = "\u05d0"
new file mode 100644
@@ -0,0 +1,48 @@
+From 44713e1252442331fd49dfca00cd42bc27859198 Mon Sep 17 00:00:00 2001
+From: Kim Davies <kim@cynosure.com.au>
+Date: Sun, 10 May 2026 12:44:47 -0700
+Subject: [PATCH] Use valid_string_length() for early oversized-input check
+
+CVE: CVE-2026-45409
+Upstream-Status: Backport [https://github.com/kjd/idna/commit/628fef84d3eda59321c21127e73dcd873db23ead]
+
+(cherry picked from commit 628fef84d3eda59321c21127e73dcd873db23ead)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ idna/core.py | 16 ++++++----------
+ 1 file changed, 6 insertions(+), 10 deletions(-)
+
+diff --git a/idna/core.py b/idna/core.py
+index ce995c9..db19bda 100644
+--- a/idna/core.py
++++ b/idna/core.py
+@@ -378,12 +378,9 @@ def encode(
+ if uts46:
+ s = uts46_remap(s, std3_rules, transitional)
+
+- # Reject inputs that exceed the maximum DNS domain length up-front.
+- # Each codepoint in a U-label contributes at least one octet to its
+- # A-label form, so any input longer than the domain limit cannot
+- # produce a valid A-domain. Short-circuiting here prevents per-label
+- # validation from being driven into quadratic time
+- if len(s) > 254:
++ # Reject inputs that exceed the maximum DNS domain length up-front
++ # to avoid expensive computation on long inputs.
++ if not valid_string_length(s, trailing_dot=True):
+ raise IDNAError("Domain too long")
+
+ trailing_dot = False
+@@ -424,10 +421,9 @@ def decode(
+ raise IDNAError("Invalid ASCII in A-label")
+ if uts46:
+ s = uts46_remap(s, std3_rules, False)
+- # See encode() for rationale; the same bound applies because every
+- # legal A-domain is at most 254 octets and every codepoint of a
+- # legal U-domain contributes at least one octet to its A-form.
+- if len(s) > 254:
++ # Reject inputs that exceed the maximum DNS domain length up-front
++ # to avoid expensive computation on long inputs.
++ if not valid_string_length(s, trailing_dot=True):
+ raise IDNAError("Domain too long")
+ trailing_dot = False
+ result = []
new file mode 100644
@@ -0,0 +1,72 @@
+From bd119cd4055324ece8a9bb1ef5413e3ad581b0ed Mon Sep 17 00:00:00 2001
+From: metsw24-max <metsw24@gmail.com>
+Date: Mon, 11 May 2026 20:59:30 +0530
+Subject: [PATCH] Enforce early length limits in check_label
+
+CVE: CVE-2026-45409
+Upstream-Status: Backport [https://github.com/kjd/idna/commit/e1cb465b6376f33306a26f467d197edbcd01c4b9]
+
+(cherry picked from commit e1cb465b6376f33306a26f467d197edbcd01c4b9)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ idna/core.py | 11 +++++++++++
+ tests/test_idna.py | 24 ++++++++++++++++++++++++
+ 2 files changed, 35 insertions(+)
+
+diff --git a/idna/core.py b/idna/core.py
+index db19bda..254f090 100644
+--- a/idna/core.py
++++ b/idna/core.py
+@@ -247,6 +247,17 @@ def check_label(label: Union[str, bytes, bytearray]) -> None:
+ label = label.decode("utf-8")
+ if len(label) == 0:
+ raise IDNAError("Empty Label")
++ # Reject oversized labels before per-codepoint validation runs.
++ # CONTEXTJ/CONTEXTO checks scan the whole label per codepoint, so an
++ # uncapped label drives validation into quadratic time
++ # (GHSA-65pc-fj4g-8rjx / CVE-2024-3651). encode()/decode() cap the
++ # whole-domain length; this cap protects direct callers of
++ # alabel/ulabel/check_label and the idna2008 incremental codec.
++ # Use the whole-domain bound rather than the per-label DNS bound so
++ # that UTS #46 lenient decoding of labels longer than 63 chars is
++ # preserved.
++ if not valid_string_length(label, trailing_dot=True):
++ raise IDNAError("Label too long")
+
+ check_nfc(label)
+ check_hyphen_ok(label)
+diff --git a/tests/test_idna.py b/tests/test_idna.py
+index ff24ebf..9832c39 100755
+--- a/tests/test_idna.py
++++ b/tests/test_idna.py
+@@ -93,6 +93,30 @@ class IDNATests(unittest.TestCase):
+ self.assertRaises(idna.IDNAError, idna.decode, payload)
+ self.assertLess(time.perf_counter() - start, 1.0)
+
++ def test_oversized_label_rejected_promptly(self):
++ # The whole-domain cap in encode()/decode() does not cover direct
++ # callers of alabel/ulabel/check_label, nor the idna2008
++ # incremental codec which calls alabel/ulabel per label. Without a
++ # per-label cap, a single oversized CONTEXTO-heavy label still
++ # drives validation into quadratic time.
++ import codecs
++ import time
++
++ import idna.codec # noqa: F401 (register the idna2008 codec)
++
++ payload = "・" * 8000 + "漢"
++ start = time.perf_counter()
++ self.assertRaises(idna.IDNAError, idna.check_label, payload)
++ self.assertRaises(idna.IDNAError, idna.alabel, payload)
++ self.assertRaises(idna.IDNAError, idna.ulabel, payload)
++ self.assertRaises(
++ idna.IDNAError,
++ codecs.getincrementalencoder("idna2008")().encode,
++ payload,
++ True,
++ )
++ self.assertLess(time.perf_counter() - start, 1.0)
++
+ def test_check_bidi(self):
+ la = "\u0061"
+ r = "\u05d0"
@@ -3,6 +3,10 @@ HOMEPAGE = "https://github.com/kjd/idna"
LICENSE = "BSD-3-Clause & Python-2.0 & Unicode-TOU"
LIC_FILES_CHKSUM = "file://LICENSE.md;md5=18a4795c19833413a7e2f1cb3cd3b143"
+SRC_URI += "file://CVE-2026-45409_p1.patch \
+ file://CVE-2026-45409_p2.patch \
+ file://CVE-2026-45409_p3.patch \
+ "
SRC_URI[sha256sum] = "795dafcc9c04ed0c1fb032c2aa73654d8e8c5023a7df64a53f39190ada629902"
inherit pypi python_flit_core ptest-python-pytest