CVE Notify: post #339209 — TG.ME

🚨 CVE-2026-19954
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.

pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa".

The Net::Whois::Raw library modules are not affected.

🎖@cveNotify
GitHub
CVE-2026-19954 pwhois script uses Net::IDN::Punycode directly skipping normalization steps, and queries the incorrect domain ·…
Net::IDN::Punycode explicitly warns about prepending "xn--" directly: You may be tempted to use this module directly and add/remove the ACE prefix (xn--) in your code for performance reas...