๐Ÿ” CVE Alert

CVE-2026-64193

UNKNOWN 0.0

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.

CWE CWE-95
Vendor nlnetlabs
Product net::dns
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for nlnetlabs net::dns

Be the first to know when new unknown vulnerabilities affecting nlnetlabs net::dns are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

NLNETLABS / Net::DNS
0 โ‰ค 1.55

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
net-dns.org: https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56 rt.cpan.org: https://rt.cpan.org/Ticket/Display.html?id=179945 metacpan.org: https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes openwall.com: http://www.openwall.com/lists/oss-security/2026/07/20/12

Credits

๐Ÿ” Steffen Ullrich