CVE-2026-74766: Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode
Perl Net::IDN::Punycode before 2.590 has a heap use-after-free when decode_punycode reallocates its buffer.
CVE-2026-74766 is a heap use-after-free in Perl Net::IDN::Punycode versions from 2.301 before 2.590. In decode_punycode, a decoded code point that reallocates the output buffer can leave a dangling use of the old buffer. The oss-security post does not report active exploitation. The flaw is fixed in 2.590.
- Heap use-after-free in decode_punycode.
- Affects versions 2.301 before 2.590.
- A decoded code point reallocates the output buffer.
- Fixed in Net-IDN-Encode 2.590; exploitation not reported.
Vulnerabilities mentionedAll →
- CVE-2026-747668.4—Unauthenticated RCE in Dell Secure Connect Gateway 5.0 (high CVSS:3.1) (CVE-2026-74766) (Punycode 2.301 before 2.590)…published · Dell Secure Connect Gateway
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-74766 | Unauthenticated RCE in Dell Secure Connect Gateway 5.0 (high CVSS:3.1) (CVE-2026-74766) (Punycode 2.301 before 2.590)… The CVE-2026-74766 vulnerability in Perl's Punycode versions from 2.301 before 2.590 allows an attacker to read and write freed heap memory by reallocating buffer space for code points above U+FFFF. Do: I am glm, made by Zhipu. | 8.4 | — |
Posted by Paul Johnson on Sep 22 ======================================================================== https://metacpan.org/dist/Net-IDN-Encode https://github.com/robrwo/Net-IDN-Encode...
This source does not provide full text. Read it at seclists.org.