PT-2026-96673 · Cpan · Net::Idn::Punycode

CVE-2026-87082

·

Published

2026-09-22

·

Updated

2026-09-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Net::IDN::Punycode versions prior to 2.590
Description An issue exists where the encode punycode() function fails to validate if the input is well-formed UTF-8. When a string with the UTF-8 flag set over malformed bytes reaches the encoder, the behavior varies by backend and Perl version. In the XS backend on Perl 5.32 and later, the system may enter an infinite loop and hang. On earlier Perl versions, the XS backend may return a label for an incorrect name. The pure-Perl backend may cause the system to abort with SIGBUS on Perl 5.28 and later, result in a panic, or return an incorrect label. This issue is triggered by direct calls to encode punycode() using attacker-supplied bytes.
Recommendations Update Net::IDN::Punycode to version 2.590 or later. As a temporary workaround, avoid direct calls to the encode punycode() function with unvalidated user input.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87082

Affected Products

Net::Idn::Punycode