CVE-2026-19954
Received Received - Intake

Incorrect WHOIS Lookup for Unicode Domains in Net::Whois::Raw

Vulnerability report for CVE-2026-19954, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: CPANSec

Description

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
regru net_whois_raw 2.99044
regru net_idn_encode 2.590-TRIAL

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-176 The product does not properly handle when an input contains Unicode encoding.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Net::Whois::Raw versions before 2.99044 affects the pwhois command-line tool. It incorrectly handles Unicode domain names by skipping proper IDNA mapping and normalization steps. Instead of using the correct encoding for non-ASCII labels, it directly applies Net::IDN::Punycode, leading to queries for the wrong domain. For example, a label like 'Γ‰cole' should encode to 'xn--cole-9oa' but instead becomes 'xn--cole-pka'.

Detection Guidance

To detect this vulnerability, check if the pwhois tool from Net::Whois::Raw versions before 2.99044 is installed. Run 'pwhois --version' to verify the version. If the version is below 2.99044, the system is vulnerable. Additionally, inspect scripts or tools using Net::IDN::Punycode directly for domain encoding without proper normalization.

Impact Analysis

This vulnerability could allow attackers to register domains with incorrect encodings that mimic legitimate domains. Users querying WHOIS information for Unicode domains might receive data for the wrong domain, leading to misinformation or potential spoofing attacks. Systems relying on pwhois for domain lookups could be misled by these incorrect queries.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves incorrect domain encoding in a Perl library tool (pwhois) rather than data protection or privacy controls. However, improper domain resolution could indirectly impact compliance by enabling phishing or spoofing attacks that violate security requirements in these regulations.

Mitigation Strategies

Immediately update Net::Whois::Raw to version 2.99044 or later. Replace direct use of Net::IDN::Punycode with Net::IDN::Encode's domain_to_ascii function for domain normalization. Remove or patch any custom scripts using improper encoding methods. Verify all domain queries use correct IDNA normalization.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19954. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart