CVE-2026-87080: Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode
Net::IDN::Punycode::PP Perl module before 2.590 decodes truncated punycode labels into names containing characters that were never encoded.
CVE-2026-87080 affects the pure-Perl punycode decoder in Net::IDN::Encode versions before 2.590. Truncated labels decode to names containing characters that were never encoded, which could enable IDN homograph-style spoofing in software relying on the module. The disclosure was posted to oss-security by Paul Johnson on September 22, 2026.