{"id":"CVE-2026-87079","summary":"Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode","details":"Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode.\n\nThe XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic in the label length. The pure-Perl backend downgrades its input to bytes so that substr can index it directly, but takes its working copy before the downgrade, so when the input carries the UTF-8 flag every substr on the copy scans from the start, with the same quadratic cost.\n\nNothing bounds the label length in the to-Unicode direction. The 63-byte DNS limit is checked only when converting to ASCII, so domain_to_unicode and uts46_to_unicode pass an attacker-supplied label of any length to the decoder.","modified":"2026-09-23T03:47:27.829301893Z","published":"2026-09-22T07:24:47.784Z","database_specific":{"cwe_ids":["CWE-407"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87079.json","cna_assigner":"CPANSec"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/22/14"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87079.json"},{"type":"PACKAGE","url":"https://github.com/robrwo/Net-IDN-Encode"},{"type":"FIX","url":"https://github.com/robrwo/Net-IDN-Encode/commit/00d723423b66810af26b88c552bedc61975b3078.patch"},{"type":"FIX","url":"https://github.com/robrwo/Net-IDN-Encode/commit/447c6b38ef5d4570329fa4f78690f4e14e09ba0c.patch"},{"type":"ADVISORY","url":"https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87079"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/robrwo/net-idn-encode","events":[{"introduced":"0"},{"fixed":"6b903cf0aeb82ff60e98e180a26daf3f9943f167"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.590"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.502","v2.501","Net-IDN-Encode-2.099_20131226","Net-IDN-Encode-2.099_20131225","Net-IDN-Encode-2.005","Net-IDN-Encode-2.003_2013881000","Net-IDN-Encode-2.003_2013880700","Net-IDN-Encode-2.003_2013122701","Net-IDN-Encode-2.003_2013122700","Net-IDN-Encode-2.003","Net-IDN-Encode-2.002","Net-IDN-Encode-2.001","Net-IDN-Encode-2.000_20120110","Net-IDN-Encode-2.000","Net-IDN-Encode-1.999_20120108","Net-IDN-Encode-1.999_20120107","Net-IDN-Encode-1.000","Net-IDN-Encode-0.999_20100110","Net-IDN-Encode-0.99_20091231","Net-IDN-Encode-0.99_20091216","Net-IDN-Encode-0.99_20080919","Net-IDN-Encode-0.99_20080914","Net-IDN-tools-0.99_20070912"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87079.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}