External risk intelligence

Perl Net::IDN::Punycode Decoding Flaw Allows Divergent Name Resolution

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-87080

This is a Perl library used for Punycode decoding. While it can be used in network-facing applications, it is a low-level programming dependency rather than an internet-facing service, appliance, or application itself. Public exposure depends entirely on how a developer incorporates the library into their specific application logic, making direct internet exposure uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in a Perl library for processing internationalized domain names. The issue arises from how certain encoded labels are handled, leading to potential differences in how systems interpret the same domain name. This could mean that one system might recognize a name while another rejects it.

  • A Perl library can misinterpret domain names.
  • Differing interpretations could affect system name resolution.
  • Confirm library relevance and any potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could send a specially crafted, truncated label to a system that uses the vulnerable Perl library for Punycode decoding. If the system's decoder is the pure-Perl version, it will incorrectly process the label, potentially leading to a different interpretation of the name compared to systems using the XS backend. This discrepancy could be exploited to manipulate name resolution or security checks.

  • No authentication or user interaction needed.
  • Triggered by sending a truncated label.
  • Can lead to unpredictable name resolution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a sender could craft a Punycode label that is interpreted differently by systems using the affected pure-Perl decoder compared to those using the XS backend. This discrepancy could lead to a situation where one system resolves a name, while another rejects it, potentially impacting name resolution or service behavior.

  • Name resolution services.
  • Different interpretations of Punycode labels.
  • Inconsistent service behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this vulnerability, application owners and infrastructure teams should coordinate efforts. The immediate first step is to locate all instances of the affected Perl module within your environment, determine their reachability, and assess their business criticality. Following this, identify the accountable owner for each instance and plan remediation based on the identified risk.

  • Identify application owners and infrastructure teams.
  • Locate affected Perl module instances.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Net::IDN::Punycode::PP?

Net::IDN::Punycode::PP is a Perl software library used to convert internationalized domain names (IDNs) into a format that the Domain Name System can process. It serves as a backend component for applications that need to handle non-ASCII characters in domain names, ensuring that human-readable scripts can be accurately translated into standard network-compatible labels.

What does CVE-2026-87080 mean?

This vulnerability, classified as CWE-1286, involves an error in how the software processes specific encoded labels. When the library encounters a truncated label, it continues decoding past the expected end of the input. This causes the library to derive an extra, unintended code point, creating a discrepancy between how this library and other standard decoders interpret the same data.

How is this vulnerability triggered?

An attacker triggers this by sending a specially crafted, truncated Punycode label to an application using this library. Crucially, the flaw only manifests when the application uses the pure-Perl implementation; the alternative XS-based backend correctly rejects these truncated labels. If an environment exclusively uses the XS version, it is not susceptible to this specific decoding error.

Is my system at risk?

Halo Surface Signal indicates that risk is unlikely for most infrastructures because this is a low-level programming dependency rather than an internet-facing service itself. Direct exposure is uncommon and depends entirely on whether your specific application logic takes user-provided data and passes it through this library. You should care if your applications process external domain names using the pure-Perl decoder.

What should I do to secure my environment?

Begin by auditing your software inventory to locate all instances of the Net::IDN::Punycode::PP module. Once identified, evaluate whether these instances are reachable by untrusted input and determine their role in your application's logic. Coordinate with the relevant application owners to plan updates or verify that your systems are leveraging the XS backend, which is not affected by this flaw.

References