Skip to main content
HIGH

CVE-2026-74766

CVSS v3

8.4

HIGH

EPSS Score

0.2 %

exploit probability, as of 2026-09-29

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the insertion pointer first and only then grows the buffer when the code point does not fit. The growth reallocates the buffer and updates every pointer except the insertion pointer, so the move that follows a

Technical details

Published
2026-09-22
Last Modified
2026-09-22

Frequently asked questions

What is CVE-2026-74766?

Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the insertion pointer first and only then grows the buffer when the code point does not fit. The growth reallocates the buffer and updates every pointer except the insertion pointer, so the move that follows a

Is CVE-2026-74766 actively exploited?

Active exploitation of CVE-2026-74766 has not been confirmed. Its EPSS score was 0.2% on 2026-09-29, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-74766?

CVE-2026-74766 has a CVSS v3 base score of 8.4 (HIGH severity).

Is CVE-2026-74766 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key