CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64193

criticalCVSS 9.8covered by 2 sourcesfirst seen 2026-07-20
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:"<command>"} in EXTRA-TEXT.

CSIRTS triage

What
Two vulnerabilities in the Perl DNS module could allow denial of service or remote code execution.
Who is affected
Perl applications and systems using libnet-dns-perl for DNS operations.
Urgency
Remediate immediately due to remote code execution vulnerability.
Action
Update libnet-dns-perl to the patched version from DSA-6459-1.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64193

Get an email if CVE-2026-64193 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64193

CVE.org record

Embed the live status

CVE-2026-64193 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64193 status](https://www.csirts.com/badge/CVE-2026-64193)](https://www.csirts.com/cve/CVE-2026-64193)