PT-2026-96673 · Cpan · Net::Idn::Punycode
CVE-2026-87082
·
Published
2026-09-22
·
Updated
2026-09-30
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Net::IDN::Punycode versions prior to 2.590
Description
An issue exists where the
encode punycode() function fails to validate if the input is well-formed UTF-8. When a string with the UTF-8 flag set over malformed bytes reaches the encoder, the behavior varies by backend and Perl version. In the XS backend on Perl 5.32 and later, the system may enter an infinite loop and hang. On earlier Perl versions, the XS backend may return a label for an incorrect name. The pure-Perl backend may cause the system to abort with SIGBUS on Perl 5.28 and later, result in a panic, or return an incorrect label. This issue is triggered by direct calls to encode punycode() using attacker-supplied bytes.Recommendations
Update Net::IDN::Punycode to version 2.590 or later.
As a temporary workaround, avoid direct calls to the
encode punycode() function with unvalidated user input.Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Net::Idn::Punycode