SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64193

CRITICAL · CVSS 9.8 EPSS 0.83% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Versions of Net::DNS up to 1.55 for Perl are vulnerable to remote code execution due to improper handling of the EDNS EXTENDED ERROR option, specifically in the parsing of the EXTRA-TEXT field. An attacker can exploit this vulnerability by injecting malicious commands that are executed via Perl's eval function. Organizations utilizing affected versions of Net::DNS should prioritize patching this critical vulnerability to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64193
Severity
CRITICAL
CVSS
9.8
EPSS
0.83%

Original NVD Description

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.