CVE-2026-87081
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-87081 is a Denial of Service vulnerability in Net::IDN::UTS46 (part of the Net-IDN-Encode Perl distribution) caused by quadratic CPU complexity during punycode encoding of overlong domain labels. All versions before 2.590 are affected. The vulnerability was published on September 22, 2026, with a patch released in version 2.590-TRIAL. The CVSS base score is listed as 0.0 in ENISA data (severity estimate: Medium by Feedly), and the CWE classification is CWE-407 (Inefficient Algorithmic Complexity) (GitHub Advisory, Feedly).

Détails techniques

The root cause (CWE-407) lies in the to_ascii function, which punycode-encodes each DNS label before applying the 63-byte length limit. The encode_punycode function in both the pure-Perl (PP) and XS backends follows the RFC 3492 sample implementation, whose outer loop iterates once per distinct non-ASCII code point and scans the entire input on each iteration — resulting in O(n²) CPU cost for a label of n distinct non-ASCII characters. An attacker can craft a domain name or email address with an overlong label containing many distinct non-ASCII characters and submit it to any function that calls to_ascii, including domain_to_ascii and email_to_ascii. The fix moves the 63-byte length check to before the punycode encoding step, since punycode never shortens a label, allowing immediate rejection without incurring the quadratic cost (GitHub Patch 1, GitHub Patch 2).

Impact

Successful exploitation causes excessive CPU consumption on the affected server, leading to denial of service for any application that processes untrusted domain names or email addresses through Net::IDN::UTS46. The attack requires no authentication — any endpoint that accepts user-supplied domain or email input and passes it through domain_to_ascii, email_to_ascii, or uts46_to_ascii is vulnerable. There is no confidentiality or integrity impact; the sole consequence is availability degradation or complete service disruption (GitHub Advisory, Feedly).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Despite the low current exploitation risk, the attack is trivially constructible by any unauthenticated user who can submit domain or email input to an affected application.

Étapes d’exploitation

  1. Identify a target: Find a web application or service that accepts user-supplied domain names or email addresses and processes them using the Perl Net::IDN::UTS46 module (versions < 2.590) — for example, a registration form, DNS lookup tool, or email validation endpoint.
  2. Craft a malicious label: Construct a domain label exceeding 63 characters composed entirely of distinct non-ASCII Unicode code points (e.g., a string of unique CJK characters such as U+3400 through U+4DB5). The quadratic cost scales with the number of distinct code points, so maximizing uniqueness maximizes CPU consumption.
  3. Submit the payload: Send the crafted domain or email string (e.g., <overlong-non-ascii-label>.example.com) to the target endpoint via HTTP request, API call, or any other input vector.
  4. Trigger CPU exhaustion: The to_ascii function encodes the label with encode_punycode before checking the 63-byte limit, causing the server to perform O(n²) work. Repeated or concurrent submissions amplify the effect, potentially exhausting CPU resources and causing denial of service (GitHub Patch 1, GitHub Advisory).

Indicateurs de compromis

  • Network: Repeated HTTP requests containing domain names or email addresses with unusually long labels composed of non-ASCII (e.g., CJK) characters submitted to input-processing endpoints.
  • Process: Sustained high CPU utilization on Perl worker processes handling domain/email validation; processes appearing stuck or unresponsive for extended periods.
  • Logs: Application logs showing repeated calls to domain_to_ascii, email_to_ascii, or uts46_to_ascii with inputs containing labels longer than 63 characters; timeout errors or worker process restarts correlated with such inputs.
  • Application: Increased request latency or service unavailability coinciding with submissions of internationalized domain name (IDN) inputs from a single or small set of source IPs.

Atténuation et solutions de contournement

Upgrade Net-IDN-Encode to version 2.590 or later, which rejects overlong labels before the punycode encoding step, eliminating the quadratic cost (MetaCPAN, GitHub Advisory). If immediate patching is not possible, implement input validation at the application layer to reject domain labels exceeding 63 characters (or email/domain strings with labels longer than 59 characters before the xn-- prefix) before they reach the Net::IDN::UTS46 functions. Rate-limiting or length-capping user-supplied domain/email inputs at the network or application boundary can also reduce exposure.

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Affecté

bookworm

libnet-idn-encode-perl

Affecté

sid

libnet-idn-encode-perl

Affecté

trixie

libnet-idn-encode-perl

Affecté

Ubuntu

Inconnu

bionic (esm-apps)

libnet-idn-encode-perl

Inconnu

devel

libnet-idn-encode-perl

Inconnu

focal (esm-apps)

libnet-idn-encode-perl

Inconnu

jammy

libnet-idn-encode-perl

Inconnu

jammy (esm-apps)

libnet-idn-encode-perl

Inconnu

noble

libnet-idn-encode-perl

Inconnu

noble (esm-apps)

libnet-idn-encode-perl

Inconnu

resolute

libnet-idn-encode-perl

Inconnu

SourceCe rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-91018HIGH8.7
  • Linux Debian logoLinux Debian
  • lwip
NonNonSep 22, 2026
CVE-2026-91777HIGH7.5
  • Linux Debian logoLinux Debian
  • jackson-databind
NonNonSep 23, 2026
CVE-2026-91776HIGH7.5
  • Linux Debian logoLinux Debian
  • jackson-databind
NonNonSep 23, 2026
CVE-2026-89425HIGH7.5
  • Linux Debian logoLinux Debian
  • pki-ca
NonNonSep 23, 2026
CVE-2026-82331NONEN/A
  • Linux Debian logoLinux Debian
  • buildstream
NonNonSep 23, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités