CVE-2026-19954: Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names.
pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa".
The Net::Whois::Raw library modules are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Net::Whois::Rawto a version that resolves this vulnerability.Fixed in 2.99044
Event History
Frequently Asked Questions
Which deployments are affected?
Only the bundled pwhois command-line tool is affected in Net::Whois::Raw versions before 2.99044. The Net::Whois::Raw library modules are not affected.
What input is required to trigger the incorrect lookup?
The issue occurs when pwhois is used with a Unicode domain label that requires IDNA mapping or normalization, such as labels containing uppercase letters outside the ASCII and Cyrillic ranges or labels that are not in NFC form.
What happens when pwhois processes an affected domain name?
pwhois may query WHOIS for a different A-label than the domain's IDNA form. For example, a label beginning with U+00C9 followed by "cole" is encoded as xn--cole-pka rather than xn--cole-9oa.