Junglewise Threat Intelligence

CVE-2026-74766: Net::IDN::Punycode heap use-after-free in decode_punycode

CVE-2026-74766 · Severity: high · CVSS 8.4 · Published 2026-09-22

Technologies: CPAN Net::IDN::Punycode. Vendors: CPAN.

Executive brief

Net::IDN::Punycode is a Perl library that decodes internationalized domain names. Versions 2.301 through 2.589 contain a memory safety bug in the C-based XS decoder that allows an attacker to read and write freed heap memory by crafting a malicious punycode-encoded domain label. An attacker could exploit this to cause crashes, information disclosure, or potentially arbitrary code execution.

Technical details

The XS backend's decode_punycode function computes an insertion pointer into the output buffer before growing the buffer to accommodate new bytes. When the buffer is reallocated during growth, all internal pointers are updated except the insertion pointer, which remains stale. Subsequent memory operations use the freed pointer. The vulnerability is triggered when decoding code points above U+FFFF (which require 4 bytes in UTF-8) in labels long enough to force buffer reallocation. The fix moves the buffer growth before pointer calculation.

Affected products

  • CPAN Net::IDN::Punycode 2.301 through 2.589

Timeline

  • 2026-09-22: disclosed
  • 2026-08-17: patched: Fix committed upstream in Net-IDN-Encode repository

References

Related threats