๐Ÿ” CVE Alert

CVE-2026-19954

UNKNOWN 0.0

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected.

CWE CWE-176
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new unknown vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/NALOBIN/Net-Whois-Raw-2.99044/changes security.metacpan.org: https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch github.com: https://github.com/regru/Net-Whois-Raw/issues/34 github.com: https://github.com/regru/Net-Whois-Raw/pull/35 metacpan.org: https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/view/lib/Net/IDN/Punycode.pm#WARNING rfc-editor.org: https://www.rfc-editor.org/rfc/rfc5891#section-5.2