CVE-2026-19954

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.

pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by 'cole' encodes to 'xn--cole-pka' rather than 'xn--cole-9oa'.

The Net::Whois::Raw library modules are not affected.

176

Improper Handling of Unicode Encoding

Draft
Common Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Unexpected State
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/regru/Net-Whois-Raw/issues/34
https://github.com/regru/Net-Whois-Raw/pull/35
https://metacpan.org/release/NALOBIN/Net-Whois-Raw-2.99044/changes
https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/view/lib/Net/IDN/P…
https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1…
https://www.rfc-editor.org/rfc/rfc5891#section-5.2