CVE-2026-19954
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.
pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa".
The Net::Whois::Raw library modules are not affected.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-176
Referencias
- https://github.com/regru/Net-Whois-Raw/issues/34
- https://github.com/regru/Net-Whois-Raw/pull/35
- https://metacpan.org/release/NALOBIN/Net-Whois-Raw-2.99044/changes
- https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/view/lib/Net/IDN/Punycode.pm#WARNING
- https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch
- https://www.rfc-editor.org/rfc/rfc5891#section-5.2
- http://www.openwall.com/lists/oss-security/2026/10/05/9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-19954",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://github.com/regru/Net-Whois-Raw",
"modules": [
"Net::Whois::Raw"
],
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.99044",
"versionType": "custom"
}
],
"packageURL": "pkg:cpan/Net-Whois-Raw",
"packageName": "Net-Whois-Raw",
"programFiles": [
"bin/pwhois"
],
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "to_punycode"
}
]
}
]
}
],
"published": "2026-10-05T07:16:30.820",
"references": [
{
"url": "https://github.com/regru/Net-Whois-Raw/issues/34",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://github.com/regru/Net-Whois-Raw/pull/35",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://metacpan.org/release/NALOBIN/Net-Whois-Raw-2.99044/changes",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/view/lib/Net/IDN/Punycode.pm#WARNING",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://www.rfc-editor.org/rfc/rfc5891#section-5.2",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/10/05/9",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Received",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-176"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.\n\npwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by \"cole\" encodes to \"xn--cole-pka\" rather than \"xn--cole-9oa\".\n\nThe Net::Whois::Raw library modules are not affected."
}
],
"lastModified": "2026-10-05T19:17:19.690",
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}