PT-2026-96669 · Cpan · Net::Idn::Punycode
CVE-2026-87078
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Net::IDN::Punycode versions 2.302 through 2.589
Description
An issue exists in the XS backend where the output buffer is leaked whenever a label is rejected in the
decode punycode() function. The XS backend allocates a scalar before validating input, sizing the buffer at twice the input length. Because the scalar is only released upon success, any of the three croaks that reject a label leave the scalar and its buffer allocated. Since the 63-byte DNS limit is only checked during ASCII conversion, there is no bound on label length when converting to Unicode. An attacker providing invalid labels can cause the process memory to grow by twice the label length for each rejected call.Recommendations
Update Net::IDN::Punycode to version 2.590 or later.
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net::Idn::Punycode