Back to overview

CVE-2026-64193

Description
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.

Metadata

CVE ID
CVE-2026-64193
State
PUBLISHED
Assigner
CPANSec
Reserved
2026-07-19 10:13 UTC
Published
2026-07-20 17:54 UTC
Last updated
2026-07-20 20:30 UTC
Primary CWE
CWE-95
CWE-95 Improper Neutralization of Directives in Dynamically …
Vendor / Product
NLNETLABS / Net::DNS
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
NLNETLABS Net::DNS 0 ≤ 1.55
Weakness (CWE)
CWESourceDescription
CWE-95 cna CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Back to overview