CVE-2026-19954: CWE-176 Improper Handling of Unicode Encoding
Description
Net::Whois::Raw versions before 2.99044 for Perl include a pwhois command-line tool that incorrectly handles Unicode domain names. The tool encodes non-ASCII labels using Net::IDN::Punycode but skips important IDNA mapping and normalization steps, causing it to query WHOIS for incorrect domain names. This affects domain labels with uppercase letters outside ASCII and Cyrillic or labels not in NFC normalization form. The core Net::Whois::Raw library modules are not affected.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Net::Whois::Raw versions prior to 2.99044 lies in the pwhois command-line tool's improper handling of Unicode domain names. The tool encodes each non-ASCII label by directly applying Net::IDN::Punycode and prepending 'xn--', but it omits the IDNA mapping and normalization steps. This leads to discrepancies between the encoded domain label and its correct IDNA form, resulting in queries to incorrect WHOIS domains. For example, a label starting with U+00C9 followed by 'cole' is encoded as 'xn--cole-pka' instead of the correct 'xn--cole-9oa'. The vulnerability is categorized under CWE-176 (Improper Handling of Unicode Encoding). The main Net::Whois::Raw library modules are unaffected by this issue.
Potential Impact
The impact is limited to the pwhois command-line tool querying WHOIS servers for incorrect domain names when Unicode domain labels are used. This can cause inaccurate WHOIS lookups and potentially mislead users or automated systems relying on pwhois for domain information. There is no indication of direct security compromise or code execution. The core Net::Whois::Raw library modules remain unaffected.
Mitigation Recommendations
A fix is available in Net::Whois::Raw version 2.99044 and later. Users should upgrade to version 2.99044 or newer to ensure correct Unicode domain name handling in the pwhois tool. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-08-15T21:45:07.158Z
- State
- PUBLISHED
Threat ID: 6ac34bd62cdf04f656ce0c51
Added to database: 10/05/2026, 07:03:50 UTC
Last enriched: 10/05/2026, 07:18:13 UTC
Last updated: 10/05/2026, 07:18:58 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.