PT-2026-96669 · Cpan · Net::Idn::Punycode

CVE-2026-87078

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Net::IDN::Punycode versions 2.302 through 2.589
Description An issue exists in the XS backend where the output buffer is leaked whenever a label is rejected in the decode punycode() function. The XS backend allocates a scalar before validating input, sizing the buffer at twice the input length. Because the scalar is only released upon success, any of the three croaks that reject a label leave the scalar and its buffer allocated. Since the 63-byte DNS limit is only checked during ASCII conversion, there is no bound on label length when converting to Unicode. An attacker providing invalid labels can cause the process memory to grow by twice the label length for each rejected call.
Recommendations Update Net::IDN::Punycode to version 2.590 or later.

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87078

Affected Products

Net::Idn::Punycode