{"id":"UBUNTU-CVE-2026-87079","details":"Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic in the label length. The pure-Perl backend downgrades its input to bytes so that substr can index it directly, but takes its working copy before the downgrade, so when the input carries the UTF-8 flag every substr on the copy scans from the start, with the same quadratic cost. Nothing bounds the label length in the to-Unicode direction. The 63-byte DNS limit is checked only when converting to ASCII, so domain_to_unicode and uts46_to_unicode pass an attacker-supplied label of any length to the decoder.","modified":"2026-09-22T22:58:27.645235857Z","published":"2026-09-22T00:00:00Z","upstream":["CVE-2026-87079"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-87079"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-87079"},{"type":"REPORT","url":"https://lists.security.metacpan.org/cve-announce/msg/43753023/"},{"type":"REPORT","url":"https://github.com/robrwo/Net-IDN-Encode/commit/00d723423b66810af26b88c552bedc61975b3078.patch"},{"type":"REPORT","url":"https://github.com/robrwo/Net-IDN-Encode/commit/447c6b38ef5d4570329fa4f78690f4e14e09ba0c.patch"},{"type":"REPORT","url":"https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/changes"}],"affected":[{"package":{"name":"libnet-idn-encode-perl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libnet-idn-encode-perl?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.202-1","2.300-1","2.300-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.300-1build1","binary_name":"libnet-idn-encode-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87079.json"}},{"package":{"name":"libnet-idn-encode-perl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libnet-idn-encode-perl?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.400-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.400-1build1","binary_name":"libnet-idn-encode-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87079.json"}},{"package":{"name":"libnet-idn-encode-perl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libnet-idn-encode-perl?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.500-1","2.500-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnet-idn-encode-perl","binary_version":"2.500-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87079.json"}},{"package":{"name":"libnet-idn-encode-perl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libnet-idn-encode-perl?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.500-1build2","2.500-2","2.500-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnet-idn-encode-perl","binary_version":"2.500-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87079.json"}},{"package":{"name":"libnet-idn-encode-perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libnet-idn-encode-perl?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.500-3","2.500-3build1","2.500-3build2","2.500-5"],"ecosystem_specific":{"binaries":[{"binary_name":"libnet-idn-encode-perl","binary_version":"2.500-5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87079.json"}},{"package":{"name":"libnet-idn-encode-perl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libnet-idn-encode-perl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.500-5build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.500-5build1","binary_name":"libnet-idn-encode-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87079.json"}}],"schema_version":"1.9.0","severity":[{"type":"Ubuntu","score":"medium"}]}