CVE-2026-87082: Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode
Perl Net::IDN::Punycode before 2.590 can hang, crash, or mislabel malformed UTF-8.
Paul Johnson disclosed CVE-2026-87082 in Net::IDN::Punycode, part of the Perl Net-IDN-Encode distribution, affecting versions before 2.590. The encode_punycode function does not validate malformed UTF-8 and can hang, crash, or return an incorrect label. The report was posted to oss-security with links to the MetaCPAN distribution and the robrwo/Net-IDN-Encode repository. No exploitation is described.