{"id":"DEBIAN-CVE-2026-19954","details":"Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.  pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by \"cole\" encodes to \"xn--cole-pka\" rather than \"xn--cole-9oa\".  The Net::Whois::Raw library modules are not affected.","modified":"2026-10-06T05:00:06.593964971Z","published":"2026-10-05T07:16:30.820Z","upstream":["CVE-2026-19954"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-19954"}],"affected":[{"package":{"name":"libnet-whois-raw-perl","ecosystem":"Debian:12","purl":"pkg:deb/debian/libnet-whois-raw-perl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.43-1.1","2.99042-1","2.99043-1","2.99043-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19954.json"}},{"package":{"name":"libnet-whois-raw-perl","ecosystem":"Debian:13","purl":"pkg:deb/debian/libnet-whois-raw-perl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.43-1.1","2.99042-1","2.99043-1","2.99043-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19954.json"}},{"package":{"name":"libnet-whois-raw-perl","ecosystem":"Debian:14","purl":"pkg:deb/debian/libnet-whois-raw-perl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.43-1.1","2.99042-1","2.99043-1","2.99043-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19954.json"}}],"schema_version":"1.9.0"}