Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-87080: Perl IDN library can decode bad domain into wrong name
CVE-2026-87080 · published 7 days ago
Summary
The Perl IDN encoding packages used on Debian and Canonical systems may interpret a malformed domain label as a different name than intended. This can cause inconsistent handling of web addresses between systems. Update the libnet-idn-encode-perl package to version 2.590 or later to fix the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | libnet-idn-encode-perl | All versions |
| Ubuntu:16.04:LTS | canonical | libnet-idn-encode-perl | All versions |
Original advisory text
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end. The empty string converts to a digit value below the range, reducing the accumulator, and the decoder derives one extra code point and its position from it. The result is deterministic. The XS backend rejects the same label. Net::IDN::Punycode uses this backend wherever the XS does not build. The two backends disagree about what such a label means, so a sender can pick a label that one installation resolves to a name and another rejects.
References
- https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/changes Third Party Advisory
- https://github.com/robrwo/Net-IDN-Encode/commit/48436c7ad2c4d4c6398110e11133754f... Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-87080 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/22/15 URL
- https://cpan.org/modules URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87080... Vendor Advisory
- https://github.com/robrwo/Net-IDN-Encode Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-87080 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-87080 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-87080 Third Party Advisory
- https://lists.security.metacpan.org/cve-announce/msg/43753025/ Third Party Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-1286Improper Validation of Syntactic Correctness of Input
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Sources
CVE-2026-87080 · NVD
CVE-2026-87080 · MITRE
DEBIAN-CVE-2026-87080 · OSV
CVE-2026-87080 · OSV
UBUNTU-CVE-2026-87080 · OSV
Track software like this
Free during beta