Junglewise Threat Intelligence

CVE-2026-87079: Net::IDN::Punycode CPU exhaustion via quadratic insertion cost

CVE-2026-87079 · Severity: high · CVSS 7.5 · Published 2026-09-22

Technologies: CPAN Net::IDN::Punycode. Vendors: CPAN.

Executive brief

Net::IDN::Punycode is a Perl library that decodes internationalized domain names. An attacker can trigger unbounded CPU exhaustion by sending a very long domain label to the decoder, causing it to perform quadratic work. Since the library's Unicode conversion functions do not enforce the DNS 63-byte label limit, a remote attacker can cause denial of service without authentication.

Technical details

The vulnerability exists in the decode_punycode function in both the XS and pure-Perl backends. The XS backend scans a UTF-8 output buffer from the start for each inserted code point, creating quadratic complexity. The pure-Perl backend has the same issue due to UTF-8 flag handling in substr operations. The domain_to_unicode and uts46_to_unicode functions pass attacker-supplied labels of any length directly to the decoder, bypassing the 63-byte DNS limit check that only applies during ASCII conversion.

Affected products

  • cpan Net::IDN::Punycode before 2.590

Timeline

  • 2026-09-22: disclosed: CVE-2026-87079 published

References

Related threats