OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-87079

HIGH · CVSS 7.5 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Versions of Net::IDN::Punycode prior to 2.590 for Perl are vulnerable to CPU exhaustion attacks due to a quadratic insertion cost when decoding long labels in the decode_punycode function. This vulnerability allows attackers to craft excessively long input labels, leading to significant performance degradation and potential denial-of-service conditions. Organizations utilizing affected versions of this library should prioritize patching to mitigate the risk of resource exhaustion attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87079
Severity
HIGH
CVSS
7.5
EPSS
0.63%

Original NVD Description

Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic in the label length. The pure-Perl backend downgrades its input to bytes so that substr can index it directly, but takes its working copy before the downgrade, so when the input carries the UTF-8 flag every substr on the copy scans from the start, with the same quadratic cost. Nothing bounds the label length in the to-Unicode direction. The 63-byte DNS limit is checked only when converting to ASCII, so domain_to_unicode and uts46_to_unicode pass an attacker-supplied label of any length to the decoder.