OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-87080

CRITICAL · CVSS 9.1 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions of Net::IDN::Punycode::PP prior to 2.590 for Perl are vulnerable to a critical flaw that allows the decoding of truncated labels, potentially leading to the generation of incorrect domain names. This discrepancy between the pure-Perl decoder and the XS backend can be exploited to create labels that are accepted by one installation but rejected by another, facilitating domain spoofing attacks. Organizations using affected versions should prioritize immediate updates to mitigate the risk of exploitation and ensure consistent domain resolution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87080
Severity
CRITICAL
CVSS
9.1
EPSS
0.63%

Original NVD Description

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end. The empty string converts to a digit value below the range, reducing the accumulator, and the decoder derives one extra code point and its position from it. The result is deterministic. The XS backend rejects the same label. Net::IDN::Punycode uses this backend wherever the XS does not build. The two backends disagree about what such a label means, so a sender can pick a label that one installation resolves to a name and another rejects.