PT-2026-96671 · Cpan · Net::Idn::Punycode::Pp

CVE-2026-87080

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Net::IDN::Punycode::PP versions prior to 2.590
Description The decode punycode function in the pure-Perl decoder incorrectly handles truncated labels. The decoder uses a four-argument substr to read digits and checks the result with defined to identify the end of the input. Because substr returns an empty string instead of undef when the string is exhausted, the decoding process continues beyond the input end. This empty string is converted to a digit value below the expected range, which reduces the accumulator and causes the decoder to derive an additional code point and position. This behavior creates a discrepancy between the pure-Perl backend and the XS backend, as the latter rejects such labels. Consequently, a sender could provide a label that is resolved to a name on one installation but rejected on another.
Recommendations Update to version 2.590 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87080

Affected Products

Net::Idn::Punycode::Pp