OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-87081

HIGH · CVSS 7.5 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects versions of Net::IDN::UTS46 prior to 2.590 for Perl, allowing attackers to exploit quadratic punycode encoding, which can lead to CPU exhaustion by processing excessively long labels before the length check is applied. This can result in denial-of-service conditions for applications relying on the affected library for domain and email address conversions. Organizations utilizing Perl applications that handle non-ASCII characters in domain names or email addresses should prioritize patching to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87081
Severity
HIGH
CVSS
7.5
EPSS
0.63%

Original NVD Description

Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte DNS limit. encode_punycode in both backends follows the sample implementation in RFC 3492, whose outer loop runs once per distinct non-ASCII code point and scans the whole input each round, so a label of distinct non-ASCII characters costs the square of its length before the limit rejects it. Every ASCII conversion in the distribution, including domain_to_ascii and email_to_ascii, goes through to_ascii.