Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.

pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa".

The Net::Whois::Raw library modules are not affected.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Apply the patch. For deployments that cannot apply the patch, convert the domain name to its A-label form, for example with Net::IDN::Encode::domain_to_ascii, before passing it to pwhois. pwhois passes all-ASCII names through unchanged.

History

Mon, 05 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected.
Title Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names
Weaknesses CWE-176
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-10-05T06:54:09.352Z

Reserved: 2026-08-15T21:45:07.158Z

Link: CVE-2026-19954

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T07:16:30.820

Modified: 2026-10-05T07:16:30.820

Link: CVE-2026-19954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses