CVE-2026-19954
N/A
Summary
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.
pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn–. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn–cole-pka" rather than "xn–cole-9oa".
The Net::Whois::Raw library modules are not affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
0 < 2.99044 | affected |
Weaknesses
- CWE-176: CWE-176 Improper Handling of Unicode Encoding
Workarounds
Apply the patch.
For deployments that cannot apply the patch, convert the domain name to its A-label form, for example with Net::IDN::Encode::domain_to_ascii, before passing it to pwhois. pwhois passes all-ASCII names through unchanged.
ADP Enrichment
CVE Program Container
Additional References
References
- https://metacpan.org/release/NALOBIN/Net-Whois-Raw-2.99044/changes
- https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch
- https://github.com/regru/Net-Whois-Raw/issues/34
- https://github.com/regru/Net-Whois-Raw/pull/35
- https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/view/lib/Net/IDN/Punycode.pm#WARNING
- https://www.rfc-editor.org/rfc/rfc5891#section-5.2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.