pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa".
The Net::Whois::Raw library modules are not affected.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Apply the patch. For deployments that cannot apply the patch, convert the domain name to its A-label form, for example with Net::IDN::Encode::domain_to_ascii, before passing it to pwhois. pwhois passes all-ASCII names through unchanged.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected. | |
| Title | Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names | |
| Weaknesses | CWE-176 | |
| References |
|
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-10-05T06:54:09.352Z
Reserved: 2026-08-15T21:45:07.158Z
Link: CVE-2026-19954
No data.
Status : Received
Published: 2026-10-05T07:16:30.820
Modified: 2026-10-05T07:16:30.820
Link: CVE-2026-19954
No data.
OpenCVE Enrichment
Updated: 2026-10-05T08:30:04Z
-
CWE-176
Improper Handling of Unicode Encoding