GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
https://lists.gnu.org/archive/html/help-libidn/2026-06/msg00001.html
https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html