Denial of Service Vulnerability in Net::DNS for Perl Software by NLNETLABS
CVE-2026-64194

Currently unrated

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-64194?

The Net::DNS library for Perl is susceptible to Denial of Service attacks due to its handling of deep DNS compression pointer chains. When decoding DNS messages, particularly with larger TCP responses, the library may recurse into itself without a limiting depth, potentially leading to excessive call stack usage. Attackers can exploit this flaw by crafting DNS packets that create a long chain of compression pointers, risking an overflow of the call stack and resulting in application crashes or services becoming unavailable. This vulnerability emphasizes the need for proper validation and checks when processing untrusted DNS data.

Affected Version(s)

Net::DNS 0 <= 1.55

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steffen Ullrich
.