PT-2026-96672 · Cpan · Net::Idn::Uts46

CVE-2026-87081

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Net::IDN::UTS46 versions prior to 2.590
Description An issue exists where CPU exhaustion can occur due to quadratic punycode encoding of an overlong label. This happens because the to ascii function performs punycode encoding on each label before applying the 63-byte DNS limit. The encode punycode function in both backends follows the RFC 3492 sample implementation, where the outer loop runs once per distinct non-ASCII code point and scans the entire input each round. Consequently, a label consisting of distinct non-ASCII characters results in processing costs proportional to the square of its length before the limit is enforced. This affects all ASCII conversions in the distribution, including domain to ascii and email to ascii, as they all utilize the to ascii function.
Recommendations Update to version 2.590 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87081

Affected Products

Net::Idn::Uts46