Description
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.

pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa".

The Net::Whois::Raw library modules are not affected.
Published: 2026-10-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Falsified WHOIS queries for Unicode domains
Action: Patch immediately
AI Analysis

Impact

The pwhois command‑line tool in Net::Whois::Raw versions before 2.99044 constructs A‑labels for Unicode domain labels by encoding each non‑ASCII label but omitting full IDNA mapping and normalization. This results in an A‑label that does not match the canonical IDNA form, meaning the WHOIS query is sent for a different domain than intended. The tool’s behavior may cause users to receive WHOIS records for the wrong domain, leading to confusion, incorrect data disclosure, and potential facilitation of phishing or delegating domain lookup errors. The weakness is a format‑string / IDNA handling flaw (CWE‑176).

Affected Systems

The vulnerability affects any installation of Net::Whois::Raw for Perl using a version prior to 2.99044 that relies on the pwhois command‑line tool. Users who employ this tool to query Unicode domain names are exposed. The library modules themselves are not impacted, only the command‑line interface. Systems with older Net::Whois::Raw should be identified and updated as described below.

Risk and Exploitability

The vulnerability is exploitable by locally running the pwhois tool with crafted Unicode domain names. No remote network or privilege escalation is required; the attacker only needs influence over the input supplied to the command. Because the exploit is straightforward and does not rely on undisclosed conditions, the risk is considered moderate. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Applying the official patch or following the workaround to convert the domain name to its ASCII A‑label form mitigates the risk.

Generated by OpenCVE AI on October 5, 2026 at 08:21 UTC.

Remediation

Vendor Workaround

Apply the patch. For deployments that cannot apply the patch, convert the domain name to its A-label form, for example with Net::IDN::Encode::domain_to_ascii, before passing it to pwhois. pwhois passes all-ASCII names through unchanged.


OpenCVE Recommended Actions

  • Upgrade Net::Whois::Raw to version 2.99044 or later to fix the A‑label construction bug.
  • If the upgrade is not possible, preprocess Unicode domain names using Net::IDN::Encode::domain_to_ascii and then supply the ASCII A‑label to pwhois.
  • Avoid using pwhois with raw Unicode input; enforce input validation or conversion to ASCII before invoking the tool.

Generated by OpenCVE AI on October 5, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected.
Title Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names
Weaknesses CWE-176
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-10-05T06:54:09.352Z

Reserved: 2026-08-15T21:45:07.158Z

Link: CVE-2026-19954

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T07:16:30.820

Modified: 2026-10-05T07:16:30.820

Link: CVE-2026-19954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T08:30:04Z

Weaknesses
  • CWE-176

    Improper Handling of Unicode Encoding