Punycode Decoding Flaw in Net::IDN::Punycode::PP Affects Perl Applications
CVE-2026-87080

Currently unrated

Key Information:

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-87080?

A vulnerability exists in the Punycode decoder of Net::IDN::Punycode::PP prior to version 2.590, which could cause improper handling of truncated labels. The pure-Perl decoder processes input one digit at a time, potentially leading to the generation of invalid names. This mismatch allows a sender to exploit the difference between the pure-Perl and XS backend decoders. Consequently, this exploitation may allow for arbitrary resolution discrepancies between installations, compromising data integrity across applications that rely on Punycode encoding.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.