CVE-2026-19954

medium

Description

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected.

References

https://www.rfc-editor.org/rfc/rfc5891#section-5.2

https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch

https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/view/lib/Net/IDN/Punycode.pm#WARNING

https://metacpan.org/release/NALOBIN/Net-Whois-Raw-2.99044/changes

https://github.com/regru/Net-Whois-Raw/pull/35

https://github.com/regru/Net-Whois-Raw/issues/34

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-92267

http://www.openwall.com/lists/oss-security/2026/10/05/9

Details

Source: Mitre, NVD

Published: 2026-10-05

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00179