Punycode Decoding Flaw in Net::IDN::Punycode::PP Affects Perl Applications
CVE-2026-87080
Currently unrated
What is CVE-2026-87080?
A vulnerability exists in the Punycode decoder of Net::IDN::Punycode::PP prior to version 2.590, which could cause improper handling of truncated labels. The pure-Perl decoder processes input one digit at a time, potentially leading to the generation of invalid names. This mismatch allows a sender to exploit the difference between the pure-Perl and XS backend decoders. Consequently, this exploitation may allow for arbitrary resolution discrepancies between installations, compromising data integrity across applications that rely on Punycode encoding.
