Executive brief
Net::IDN::Punycode is a Perl library that decodes internationalized domain names. An attacker can trigger unbounded CPU exhaustion by sending a very long domain label to the decoder, causing it to perform quadratic work. Since the library's Unicode conversion functions do not enforce the DNS 63-byte label limit, a remote attacker can cause denial of service without authentication.
Technical details
The vulnerability exists in the decode_punycode function in both the XS and pure-Perl backends. The XS backend scans a UTF-8 output buffer from the start for each inserted code point, creating quadratic complexity. The pure-Perl backend has the same issue due to UTF-8 flag handling in substr operations. The domain_to_unicode and uts46_to_unicode functions pass attacker-supplied labels of any length directly to the decoder, bypassing the 63-byte DNS limit check that only applies during ASCII conversion.
Affected products
- cpan Net::IDN::Punycode before 2.590
Timeline
- 2026-09-22: disclosed: CVE-2026-87079 published