DEBIAN-CVE-2026-19954

Source
https://security-tracker.debian.org/tracker/CVE-2026-19954
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19954.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-19954
Upstream
  • CVE-2026-19954
Published
2026-10-05T07:16:30Z
Modified
2026-10-06T05:00:06Z
Summary
[none]
Details

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected.

References

Affected packages

Debian:12 / libnet-whois-raw-perl

Package

Name
libnet-whois-raw-perl
Purl
pkg:deb/debian/libnet-whois-raw-perl?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.43-1.1
2.99042-1
2.99043-1
2.99043-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19954.json"

Debian:13 / libnet-whois-raw-perl

Package

Name
libnet-whois-raw-perl
Purl
pkg:deb/debian/libnet-whois-raw-perl?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.43-1.1
2.99042-1
2.99043-1
2.99043-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19954.json"

Debian:14 / libnet-whois-raw-perl

Package

Name
libnet-whois-raw-perl
Purl
pkg:deb/debian/libnet-whois-raw-perl?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.43-1.1
2.99042-1
2.99043-1
2.99043-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19954.json"