CVE-2026-87078
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode.
The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing bounds the label length in the to-Unicode direction, since the 63-byte DNS limit is checked only when converting to ASCII.
Only the XS backend is affected.
A sender who supplies invalid labels grows the process by twice the label length per rejected call, with no successful call needed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.65%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
AV:N/PR:N permite explotación remota sin autenticación de servicio expuesto (T1190). Memory leak en decode_punycode permite DoS por consumo de recursos (C:H/A:H). Impacto secundario: corrupción de datos en buffer de salida.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-401
Referencias
- https://github.com/robrwo/Net-IDN-Encode/commit/92572f726e48af5559de4cc8a831463b79dfb217.patch
- https://github.com/robrwo/Net-IDN-Encode/commit/edad63e0eeeeb18d93bc6dfe4d9dcdff9c244e1b.patch
- https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/changes
- http://www.openwall.com/lists/oss-security/2026/09/22/13
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-87078",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-87078",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-22T12:33:13.035011Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://github.com/robrwo/Net-IDN-Encode",
"modules": [
"Net::IDN::Punycode"
],
"versions": [
{
"status": "affected",
"version": "2.302",
"lessThan": "2.590",
"versionType": "custom"
}
],
"packageURL": "pkg:cpan/Net-IDN-Encode",
"packageName": "Net-IDN-Encode",
"programFiles": [
"lib/Net/IDN/Punycode.xs"
],
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "Net::IDN::Punycode::decode_punycode"
}
]
}
]
}
],
"published": "2026-09-22T08:16:40.530",
"references": [
{
"url": "https://github.com/robrwo/Net-IDN-Encode/commit/92572f726e48af5559de4cc8a831463b79dfb217.patch",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://github.com/robrwo/Net-IDN-Encode/commit/edad63e0eeeeb18d93bc6dfe4d9dcdff9c244e1b.patch",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/changes",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/22/13",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode.\n\nThe XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing bounds the label length in the to-Unicode direction, since the 63-byte DNS limit is checked only when converting to ASCII.\n\nOnly the XS backend is affected.\n\nA sender who supplies invalid labels grows the process by twice the label length per rejected call, with no successful call needed."
}
],
"lastModified": "2026-09-22T19:07:00.983",
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}