CVE-2026-64193
CRITICALNet::DNS <= 1.55 - Command Execution via EDNS Extended Error Eval Injection
Title source: manualDescription
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.
References (4)
Core 4
Core References
Issue Tracking issue-tracking
https://rt.cpan.org/Ticket/Display.html?id=179945
Release Notes release-notes
https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes
Scores
CVSS v3
9.8
EPSS
0.0083
EPSS Percentile
53.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-95
Status
published
Products (1)
NLNETLABS/Net::DNS
< 1.55
Published
Jul 20, 2026
Tracked Since
Jul 21, 2026