PT-2026-96666 · Cpan · Net::Idn::Punycode
CVE-2026-74765
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Net::IDN::Punycode versions prior to 2.590
Description
An out-of-bounds read occurs in the XS backend due to an integer overflow of the delta accumulator within the
encode punycode() function. The XS backend stores the punycode delta and the derived digit index as signed integers. Because the accumulation delta += (m-n) * (h+1) lacks an overflow check, a sufficiently large code point or a long label (such as 1927 ASCII letters followed by U+10FFFF) can cause the delta to wrap. This results in a digit index that falls outside the 36-entry digit table. Since the boundary check only verifies if the index is above 36, negative indices or an index of 36 are permitted, allowing the system to copy a byte from outside the digit table into the encoded result or cause the process to crash.Recommendations
Update Net::IDN::Punycode to version 2.590 or later.
Fix
Out of bounds Read
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Net::Idn::Punycode