PT-2026-96671 · Cpan · Net::Idn::Punycode::Pp
CVE-2026-87080
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Net::IDN::Punycode::PP versions prior to 2.590
Description
The
decode punycode function in the pure-Perl decoder incorrectly handles truncated labels. The decoder uses a four-argument substr to read digits and checks the result with defined to identify the end of the input. Because substr returns an empty string instead of undef when the string is exhausted, the decoding process continues beyond the input end. This empty string is converted to a digit value below the expected range, which reduces the accumulator and causes the decoder to derive an additional code point and position. This behavior creates a discrepancy between the pure-Perl backend and the XS backend, as the latter rejects such labels. Consequently, a sender could provide a label that is resolved to a name on one installation but rejected on another.Recommendations
Update to version 2.590 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net::Idn::Punycode::Pp