THREAT OPS › Threat News › [NVD] CVE-2026-64194 (HIGH 7.5) — Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains.
Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call s
[NVD] CVE-2026-64194 (HIGH 7.5) — Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call s
CVE-2026-64194 CVSS: 7.5 HIGH Published: 2026-07-20T19:17:30.157
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains.
Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call stack (at least with larger TCP responses), leading to
MITRE ATT&CK techniques
- CompressionT1027.015
Indicators of compromise
- CVE-2026-64194cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64194