Whois Command-Line Tool Vulnerability in Net::Whois::Raw for Perl
CVE-2026-19954

Currently unrated

Key Information:

Vendor

Perl

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-19954?

The pwhois command-line tool in Net::Whois::Raw versions prior to 2.99044 for Perl fails to correctly query WHOIS information for Unicode domain names. This occurs because the tool encodes non-ASCII labels directly using Net::IDN::Punycode, but it does not perform the necessary IDNA mapping and normalization steps. As a result, certain domain names may be queried incorrectly, leading to potential misrepresentation and access issues for users relying on accurate WHOIS data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.