CVE-2026-87079: Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode
Perl Net::IDN::Punycode before 2.590 can exhaust CPU decoding a long Punycode label.
Paul Johnson disclosed CVE-2026-87079 in Perl's Net::IDN::Punycode, part of Net-IDN-Encode. Versions before 2.590 can exhaust CPU because decode_punycode pays a quadratic insertion cost when decoding a long label. The issue is a denial-of-service flaw; no exploitation in the wild is reported. It is fixed in 2.590.
- Affects Net::IDN::Punycode before 2.590.
- Quadratic insertion cost in decode_punycode can exhaust CPU.
- Triggered by decoding a long label.
- Fixed in version 2.590 of Net-IDN-Encode.
Vulnerabilities mentionedAll →
- CVE-2026-870797.5—Unauthenticated RCE in Dell Secure Connect Gateway 5.0 (CVE-2026-87079)published · Dell Secure Connect Gateway 5.0
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87079 | Unauthenticated RCE in Dell Secure Connect Gateway 5.0 (CVE-2026-87079) The CVE allows CPU exhaustion in Dell Secure Connect Gateways using long Perl labels, with a high CVSS score. It was disclosed but no public PoC exists. Do: Upgrade to the latest version to eliminate CPU exhaustion. Check for any plugins with large active installs. Consider updating firewall rules or service configurations. | 7.5 | — |
Posted by Paul Johnson on Sep 22 ======================================================================== https://metacpan.org/dist/Net-IDN-Encode https://github.com/robrwo/Net-IDN-Encode Net::IDN::Punycode...
This source does not provide full text. Read it at seclists.org.