OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2016-15059

CRITICAL · CVSS 9.8 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the XS backend of Net::IDN::Punycode in Perl, where a heap buffer overflow can occur due to unchecked writes past the output buffer during the encoding process. This flaw allows an attacker to corrupt the heap by supplying a specially crafted input string, potentially leading to arbitrary code execution or denial of service. Organizations using affected versions should prioritize patching this vulnerability due to its critical severity and the risk it poses to application integrity and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2016-15059
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%

Original NVD Description

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the write of the terminating NUL do not, so an input whose encoded form fills the buffer writes past its end. Only the XS backend is affected. Encoding an attacker-supplied string corrupts the heap.