« Volver al listado

CVE-2026-19954

Estado: RecibidaSin puntuar—

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.

pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa".

The Net::Whois::Raw library modules are not affected.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-19954",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/regru/Net-Whois-Raw",
          "modules": [
            "Net::Whois::Raw"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.99044",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:cpan/Net-Whois-Raw",
          "packageName": "Net-Whois-Raw",
          "programFiles": [
            "bin/pwhois"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "to_punycode"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-10-05T07:16:30.820",
  "references": [
    {
      "url": "https://github.com/regru/Net-Whois-Raw/issues/34",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://github.com/regru/Net-Whois-Raw/pull/35",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/NALOBIN/Net-Whois-Raw-2.99044/changes",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/view/lib/Net/IDN/Punycode.pm#WARNING",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://www.rfc-editor.org/rfc/rfc5891#section-5.2",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/10/05/9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Received",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-176"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.\n\npwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by \"cole\" encodes to \"xn--cole-pka\" rather than \"xn--cole-9oa\".\n\nThe Net::Whois::Raw library modules are not affected."
    }
  ],
  "lastModified": "2026-10-05T19:17:19.690",
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}