Skip to main content

CVE-2026-19954: CWE-176 Improper Handling of Unicode Encoding

0
Medium
VulnerabilityCVE-2026-19954cvecve-2026-19954cwe-176
Published: 10/05/2026 (10/05/2026, 06:54:09 UTC)
Source: CVE Database V5

Description

Net::Whois::Raw versions before 2.99044 for Perl include a pwhois command-line tool that incorrectly handles Unicode domain names. The tool encodes non-ASCII labels using Net::IDN::Punycode but skips important IDNA mapping and normalization steps, causing it to query WHOIS for incorrect domain names. This affects domain labels with uppercase letters outside ASCII and Cyrillic or labels not in NFC normalization form. The core Net::Whois::Raw library modules are not affected.

Affected software

GitHub Actionsmore threats →cve
Net-Whois-Raw
pkg:github/Net-Whois-Raw
Affected versions
>=0 <2.99044

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 07:18:13 UTC

Technical Analysis

The vulnerability in Net::Whois::Raw versions prior to 2.99044 lies in the pwhois command-line tool's improper handling of Unicode domain names. The tool encodes each non-ASCII label by directly applying Net::IDN::Punycode and prepending 'xn--', but it omits the IDNA mapping and normalization steps. This leads to discrepancies between the encoded domain label and its correct IDNA form, resulting in queries to incorrect WHOIS domains. For example, a label starting with U+00C9 followed by 'cole' is encoded as 'xn--cole-pka' instead of the correct 'xn--cole-9oa'. The vulnerability is categorized under CWE-176 (Improper Handling of Unicode Encoding). The main Net::Whois::Raw library modules are unaffected by this issue.

Potential Impact

The impact is limited to the pwhois command-line tool querying WHOIS servers for incorrect domain names when Unicode domain labels are used. This can cause inaccurate WHOIS lookups and potentially mislead users or automated systems relying on pwhois for domain information. There is no indication of direct security compromise or code execution. The core Net::Whois::Raw library modules remain unaffected.

Mitigation Recommendations

A fix is available in Net::Whois::Raw version 2.99044 and later. Users should upgrade to version 2.99044 or newer to ensure correct Unicode domain name handling in the pwhois tool. No other mitigation is indicated or required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CPANSec
Date Reserved
2026-08-15T21:45:07.158Z
State
PUBLISHED

Threat ID: 6ac34bd62cdf04f656ce0c51

Added to database: 10/05/2026, 07:03:50 UTC

Last enriched: 10/05/2026, 07:18:13 UTC

Last updated: 10/05/2026, 07:18:58 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses