CVE-2026-19954: 
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-19954 is a vulnerability in the pwhois command-line tool shipped with the Net::Whois::Raw Perl module (versions before 2.99044) that causes it to query WHOIS for incorrect domain names when given unicode (internationalized) domain names. The root cause is improper unicode encoding: the tool uses Net::IDN::Punycode directly and prepends xn-- without performing the required IDNA mapping and normalization steps. For example, a label containing U+00C9 followed by "cole" encodes to xn--cole-pka instead of the correct IDNA form xn--cole-9oa. The vulnerability was disclosed on October 5, 2026, and is classified as Medium severity; the EUVD lists a base score of 0.0 (pending full scoring), while Feedly estimates it as Medium (Github Advisory, GitHub Issue).

Détails techniques

The vulnerability is classified as CWE-176 (Improper Handling of Unicode Encoding) and maps to CAPEC-71 (Using Unicode Encoding to Bypass Validation Logic) (Github Advisory). The pwhois tool encodes non-ASCII domain labels by calling Net::IDN::Punycode directly and prepending xn--, bypassing the IDNA 2008 mapping and NFC normalization steps required by RFC 5891. As Net::IDN::Punycode itself explicitly warns against this usage pattern, the resulting ASCII-Compatible Encoding (A-label) differs from the correct IDNA form for labels containing non-Cyrillic uppercase letters or non-NFC-normalized characters (GitHub Issue). The fix, merged in pull request #35, replaces the direct Net::IDN::Punycode call with Net::IDN::Encode::domain_to_ascii, which performs proper IDNA normalization (GitHub PR). Only the pwhois CLI tool is affected; the Net::Whois::Raw library modules themselves are not vulnerable.

Impact

Users invoking the pwhois command-line tool with unicode (internationalized) domain names will receive WHOIS data for an unintended domain rather than the queried one, leading to incorrect lookup results and potential information confusion. In a security context, an attacker could register the incorrectly encoded domain (e.g., xn--cole-pka instead of xn--cole-9oa) and cause pwhois users to unknowingly retrieve attacker-controlled WHOIS records, potentially facilitating social engineering or misleading domain ownership verification workflows (Github Advisory, GitHub Issue). There is no impact on confidentiality, integrity, or availability of the underlying system; the scope is limited to incorrect WHOIS query results.

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Github Advisory). The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is limited to scenarios where a user runs pwhois with a unicode domain name, and a threat actor has pre-registered the incorrectly encoded punycode domain to serve misleading WHOIS data.

Atténuation et solutions de contournement

Upgrade Net::Whois::Raw to version 2.99044 or later, which replaces the direct Net::IDN::Punycode call with Net::IDN::Encode::domain_to_ascii for correct IDNA encoding (GitHub PR, MetaCPAN Release). As an interim workaround for users unable to upgrade immediately, avoid using pwhois with unicode domain names, or manually convert unicode domain names to their correct IDNA punycode form (using a compliant tool) before passing them to pwhois. A patch file is also available at the MetaCPAN security patches repository for version 2.99043.

Réactions de la communauté

The vulnerability was reported by researcher robrwo via a GitHub issue on October 4, 2026, and a fix was merged by maintainer nalobin the following day, demonstrating a rapid response from the project (GitHub Issue, GitHub PR). No significant broader media coverage or notable community commentary beyond the GitHub thread has been identified.

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2019-25777HIGH8.1
  • Linux Debian logoLinux Debian
  • perl-YAML
NonOuiOct 05, 2026
CVE-2017-20285HIGH7.4
  • Linux Debian logoLinux Debian
  • libyaml-perl
NonOuiOct 05, 2026
CVE-2026-94291MEDIUM6.5
  • Linux Debian logoLinux Debian
  • epiphany-browser
NonNonOct 05, 2026
CVE-2026-97873MEDIUM5.3
  • Bouncy Castle logoBouncy Castle
  • bouncycastle
NonOuiOct 03, 2026
CVE-2026-19954NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-whois-raw-perl
NonNonOct 05, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités