PT-2026-96670 · Cpan · Net::Idn::Punycode
CVE-2026-87079
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Net::IDN::Punycode versions prior to 2.590
Description
An issue exists that allows CPU exhaustion due to quadratic insertion cost when decoding long labels in the
decode punycode() function. In the XS backend, each decoded code point is inserted into a UTF-8 buffer by scanning from the start, resulting in a cost that grows quadratically relative to the label length. Similarly, the pure-Perl backend experiences the same quadratic cost when the input carries the UTF-8 flag because substr scans from the start of the copy. This is exacerbated by the fact that no bounds are placed on label length during to-Unicode conversion, allowing domain to unicode() and uts46 to unicode() to pass labels of arbitrary length to the decoder.Recommendations
Update to version 2.590 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net::Idn::Punycode