CVE-2026-74766

CVE-2026-74766 published: Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it ...

View full NVD advisory → ← Back to CVE watch