Security Advisories (7)
CVE-2026-74765 (2026-09-22)

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a signed int. The accumulation `delta += (m-n) * (h+1)` has no overflow check, so a large enough code point wraps the delta and the digit index leaves the range of the 36-entry digit table. The bound before the final table access tests only for an index above 36, so a negative index passes it, as does 36 itself. Perl strings hold code points beyond the Unicode range, and one such code point overflows the accumulation on its own. Valid input wraps it as well, for example 1927 ASCII letters followed by U+10FFFF. The conversion functions encode a label before they check its length, so a long label reaches the encoder through the documented API. Only the XS backend is affected. Encoding an attacker-supplied string copies a byte from outside the digit table into the encoded result or crashes the process.

CVE-2026-74766 (2026-09-22)

Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the insertion pointer first and only then grows the buffer when the code point does not fit. The growth reallocates the buffer and updates every pointer except the insertion pointer, so the move that follows and the write of the code point go through a freed pointer. The buffer starts at twice the label length, and a code point above U+FFFF takes four bytes in the output, so a label of such code points outgrows it and forces the reallocation. Version 2.301, the fix for CVE-2016-15059, introduced the defect. Only the XS backend is affected. Decoding an attacker-supplied punycode label reads and writes freed heap memory.

CVE-2026-87078 (2026-09-22)

Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing bounds the label length in the to-Unicode direction, since the 63-byte DNS limit is checked only when converting to ASCII. Only the XS backend is affected. A sender who supplies invalid labels grows the process by twice the label length per rejected call, with no successful call needed.

CVE-2026-87079 (2026-09-22)

Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic in the label length. The pure-Perl backend downgrades its input to bytes so that substr can index it directly, but takes its working copy before the downgrade, so when the input carries the UTF-8 flag every substr on the copy scans from the start, with the same quadratic cost. Nothing bounds the label length in the to-Unicode direction. The 63-byte DNS limit is checked only when converting to ASCII, so domain_to_unicode and uts46_to_unicode pass an attacker-supplied label of any length to the decoder.

CVE-2026-87080 (2026-09-22)

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end. The empty string converts to a digit value below the range, reducing the accumulator, and the decoder derives one extra code point and its position from it. The result is deterministic. The XS backend rejects the same label. Net::IDN::Punycode uses this backend wherever the XS does not build. The two backends disagree about what such a label means, so a sender can pick a label that one installation resolves to a name and another rejects.

CVE-2026-87081 (2026-09-22)

Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte DNS limit. encode_punycode in both backends follows the sample implementation in RFC 3492, whose outer loop runs once per distinct non-ASCII code point and scans the whole input each round, so a label of distinct non-ASCII characters costs the square of its length before the limit rejects it. Every ASCII conversion in the distribution, including domain_to_ascii and email_to_ascii, goes through to_ascii.

CVE-2026-87082 (2026-09-22)

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed bytes, as the :utf8 PerlIO layer produces from any malformed input, reaches the encoder unchecked. On perl 5.32 and later the XS backend reports a malformed sequence with a length of `(STRLEN)-1`, so the scan steps back one byte instead of forward and never ends. On earlier perls the XS returns a valid label for a different name. The pure-Perl backend runs a regex over the flagged string. Depending on the bytes, it aborts with SIGBUS on perl 5.28 and later, dies with a panic, or returns a wrong label. The documented conversion functions match the label against Unicode properties first and that match dies on such a string, so only a direct call to encode_punycode reaches the defect. The decoder is not affected. A direct caller encoding attacker-supplied bytes hangs, crashes or gets a label for a name the input never held.

NAME

Net::IDN::Encode - Internationalizing Domain Names in Applications (IDNA)

SYNOPSIS

use Net::IDN::Encode ':all';
my $a = domain_to_ascii("müller.example.org");
my $e = email_to_ascii("POSTMASTER@例。テスト");
my $u = domain_to_unicode('EXAMPLE.XN--11B5BS3A9AJ6G');

DESCRIPTION

This module provides an easy-to-use interface for encoding and decoding Internationalized Domain Names (IDNs).

IDNs use characters drawn from a large repertoire (Unicode), but IDNA allows the non-ASCII characters to be represented using only the ASCII characters already allowed in so-called host names today (letter-digit-hyphen, /[A-Z0-9-]/i).

Use this module if you just want to convert domain names (or email addresses), using whatever IDNA standard is the best choice at the moment.

You should be familiar with Unicode support in perl, as this module expects correctly encoded input. See perlunitut, perluniintro and perlunicode for details.

UNICODE VERSION

To convert labels correctly between Unicode and ASCII, each character in the label must be present in the Unicode version supported by your perl. Consequently, this module will refuse to convert labels with new Unicode characters on older perl versions (see below).

FUNCTIONS

By default, this module does not export any subroutines. You may use the :all tag to import everything. You can also use regular expressions such as /^to_/ or /^email_/ to select some of the functions, see Exporter for details.

The following functions are available:

to_ascii( $label, %param )

Converts a single label $label to ASCII. Will throw an exception on invalid input. If $label is already a valid ASCII domain label (including most NON-LDH labels such as those used for SRV records and fake A-labels), this function will never fail but return $label as-is if conversion would fail.

This function takes the following optional parameters (%param):

AllowUnassigned

(boolean) If set to a true value, code points that are unassigned in the Unicode version supported by your perl are allowed. This is an extension over UTS #46.

While this increases the number of labels that can be converted successfully (especially on older perls) and may thus maximizes the compatibility with domain names created under future versions of Unicode, it also introduces the risk of incorrect conversions. Characters added in later versions of Unicode might have properties that affect the conversion; if these properties are not known on your version of perl, you might therefore end up with an incorrect conversion.

The default is false.

UseSTD3ASCIIRules

(boolean) If set to a true value, checks the label for compliance with STD 3 (RFC 1123) syntax for host name parts. The exact checks done depend on the IDNA standard used. Usually, you will want to set this to true.

Please note that UseSTD3ASCIIRules only affects the conversion between ASCII labels (A-labels) and Unicode labels (U-labels). Labels that are in ASCII may still be passed-through as-is.

For historical reasons, the default is false (unlike domain_to_ascii).

TransitionalProcessing

(boolean) If set to true, the conversion will be compatible with IDNA2003. This only affects four characters: 'ß' (U+00DF), 'ς' (U+03C2), ZWJ (U+200D) and ZWNJ (U+200C). Usually, you will want to set this to false.

The default is false.

This function does not handle strings that consist of multiple labels (such as domain names). Use domain_to_ascii instead.

to_unicode( $label, %param )

Converts a single label $label to Unicode. Will throw an exception on invalid input. If $label is an ASCII label (including most NON-LDH labels such as those used for SRV records), this function will not fail but return $label as-is if conversion would fail.

This function takes the same optional parameters as to_ascii, with the same defaults.

If $label is already in ASCII, this function will never fail but return $label as is as a last resort (i.e. pass-through).

This function takes the following optional parameters (%param):

AllowUnassigned
UseSTD3ASCIIRules

See to_unicode above. Please note that there is no need for TransitionalProcessing for to_unicode.

This function does not handle strings that consist of multiple labels (such as domain names). Use domain_to_unicode instead.

domain_to_ascii( $label, %param )

Converts all labels of the hostname $domain (with labels separated by dots) to ASCII (using to_ascii). Will throw an exception on invalid input.

This function takes the following optional parameters (%param):

AllowUnassigned
TransitionalProcessing

See to_unicode above.

UseSTD3ASCIIRules

(boolean) If set to a true value, checks the label for compliance with STD 3 (RFC 1123) syntax for host name parts.

The default is true (unlike to_ascii).

This function will convert all dots to ASCII, i.e. to U+002E (full stop). The following characters are recognized as dots: U+002E (full stop), U+3002 (ideographic full stop), U+FF0E (fullwidth full stop), U+FF61 (halfwidth ideographic full stop).

domain_to_unicode( $domain, %param )

Converts all labels of the hostname $domain (with labels separated by dots) to Unicode. Will throw an exception on invalid input.

This function takes the same optional parameters as domain_to_ascii, with the same defaults.

This function takes the following optional parameters (%param):

AllowUnassigned
UseSTD3ASCIIRules

See domain_to_unicode above. Please note that there is no TransitionalProcessing for domain_to_unicode.

This function will preserve the original version of dots. The following characters are recognized as dots: U+002E (full stop), U+3002 (ideographic full stop), U+FF0E (fullwidth full stop), U+FF61 (halfwidth ideographic full stop).

email_to_ascii( $email, %param )

Converts the domain part (right hand side, separated by an at sign) of an RFC 2821/2822 email address to ASCII, using domain_to_ascii. May throw an exception on invalid input.

It takes the same parameters as domain_to_ascii.

This function currently does not handle internationalization of the local-part (left hand side). Future versions of this module might implement an ASCII conversion for the local-part, should one be standardized.

This function will convert the at sign to ASCII, i.e. to U+0040 (commercial at), as well as label separators. The following characters are recognized as at signs: U+0040 (commercial at), U+FE6B (small commercial at) and U+FF20 (fullwidth commercial at).

email_to_unicode( $email, %param )

Converts the domain part (right hand side, separated by an at sign) of an RFC 2821/2822 email address to Unicode, using domain_to_unicode. May throw an exception on invalid input.

It takes the same parameters as domain_to_unicode.

This function currently does not handle internationalization of the local-part (left hand side). Future versions of this module might implement a conversion from ASCII for the local-part, should one be standardized.

This function will preserve the original version of at signs (and label separators). The following characters are recognized as at signs: U+0040 (commercial at), U+FE6B (small commercial at) and U+FF20 (fullwidth commercial at).

AUTHOR

Claus Färber

Currently maintained by Robert Rothenberg <perl@rhizomnic.com> and Paul Johnson <paul@pjcj.net>.

LICENSE

Copyright 2007-2018 Claus Färber.

Parts copyright 2026 Robert Rothenberg <perl@rhizomnic.com> and Paul Johnson <paul@pjcj.net>.

This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

SEE ALSO

Net::IDN::Punycode, Net::IDN::UTS46, Net::IDN::IDNA2003, Net::IDN::IDNA2008, UTS #46 (http://www.unicode.org/reports/tr46/), RFC 5890 (http://tools.ietf.org/html/rfc5890).