PT-2026-96670 · Cpan · Net::Idn::Punycode

CVE-2026-87079

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Net::IDN::Punycode versions prior to 2.590
Description An issue exists that allows CPU exhaustion due to quadratic insertion cost when decoding long labels in the decode punycode() function. In the XS backend, each decoded code point is inserted into a UTF-8 buffer by scanning from the start, resulting in a cost that grows quadratically relative to the label length. Similarly, the pure-Perl backend experiences the same quadratic cost when the input carries the UTF-8 flag because substr scans from the start of the copy. This is exacerbated by the fact that no bounds are placed on label length during to-Unicode conversion, allowing domain to unicode() and uts46 to unicode() to pass labels of arbitrary length to the decoder.
Recommendations Update to version 2.590 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87079

Affected Products

Net::Idn::Punycode