PT-2026-96672 · Cpan · Net::Idn::Uts46
CVE-2026-87081
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Net::IDN::UTS46 versions prior to 2.590
Description
An issue exists where CPU exhaustion can occur due to quadratic punycode encoding of an overlong label. This happens because the
to ascii function performs punycode encoding on each label before applying the 63-byte DNS limit. The encode punycode function in both backends follows the RFC 3492 sample implementation, where the outer loop runs once per distinct non-ASCII code point and scans the entire input each round. Consequently, a label consisting of distinct non-ASCII characters results in processing costs proportional to the square of its length before the limit is enforced. This affects all ASCII conversions in the distribution, including domain to ascii and email to ascii, as they all utilize the to ascii function.Recommendations
Update to version 2.590 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net::Idn::Uts46