Skip to content
Rota Nacional

Cyber ·

CVE-2026-19954: Net::Whois::Raw for Perl queries the wrong domain for Unicode domain names

CPAN Security Group advisory, published October 5, 2026 on the oss-sec list, covering Net::Whois::Raw versions before 2.99044, where the pwhois tool may query the wrong domain when the name contains Unicode characters.

CVE-2026-19954 affects the Net-Whois-Raw distribution in the Perl ecosystem, in versions before 2.99044. According to the advisory, the pwhois tool included in that distribution may query the wrong domain when the name being looked up contains Unicode characters. The text was posted by Robert Rothenberg to the oss-sec list on October 5, 2026, and the source states that it is an automatic translation of the feed content. The advisory comes from the CPAN Security Group and references the distribution page on MetaCPAN and the version control repository, which we do not reproduce here.

The practical relevance is for teams that run WHOIS lookups in scripts, inventory automation or domain analysis tools written in Perl. A query sent to the wrong destination can produce incorrect results and expose the searched name to an unintended service. As far as the available text shows, the advisory does not describe further impact, a severity score or mitigation steps beyond the fixed version.

To verify, read the original advisory on the oss-sec list, confirm the identifier in the official CVE record, and find the Net-Whois-Raw distribution on MetaCPAN, where the published versions are listed. Because the source text is an automatic translation, check technical terms against the original English before acting on them.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free