PT-2026-96666 · Cpan · Net::Idn::Punycode

CVE-2026-74765

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Net::IDN::Punycode versions prior to 2.590
Description An out-of-bounds read occurs in the XS backend due to an integer overflow of the delta accumulator within the encode punycode() function. The XS backend stores the punycode delta and the derived digit index as signed integers. Because the accumulation delta += (m-n) * (h+1) lacks an overflow check, a sufficiently large code point or a long label (such as 1927 ASCII letters followed by U+10FFFF) can cause the delta to wrap. This results in a digit index that falls outside the 36-entry digit table. Since the boundary check only verifies if the index is above 36, negative indices or an index of 36 are permitted, allowing the system to copy a byte from outside the digit table into the encoded result or cause the process to crash.
Recommendations Update Net::IDN::Punycode to version 2.590 or later.

Fix

Out of bounds Read

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74765

Affected Products

Net::Idn::Punycode