Executive brief
Net::IDN::Punycode::PP is a Perl library that decodes internationalized domain names using the Punycode standard. A flaw in the pure-Perl decoder allows it to decode truncated labels that should be rejected, fabricating characters that the XS backend would not generate. This means different Perl installations could interpret the same encoded domain name differently, potentially allowing attackers to bypass validation or trigger inconsistent behavior across systems.
Technical details
The pure-Perl decoder uses four-argument substr to read input one character at a time and tests with defined() to detect end-of-input; however, substr on an exhausted string returns an empty string rather than undef, allowing decoding to continue past the end. The empty string is treated as digit value -22, which causes the decoder to fabricate an extra code point. The XS backend correctly rejects such truncated labels, creating a backend disagreement where approximately one-fifth of random punycode labels decode to different outputs depending on which backend is loaded.
Affected products
- CPAN Net::IDN::Punycode::PP before 2.590
Timeline
- 2026-09-22: disclosed
- 2026-08-18: patched