CVE-2026-64193
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR.
Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:"<command>"} in EXTRA-TEXT.
CSIRTS triage
- What
- Two vulnerabilities in the Perl DNS module could allow denial of service or remote code execution.
- Who is affected
- Perl applications and systems using libnet-dns-perl for DNS operations.
- Urgency
- Remediate immediately due to remote code execution vulnerability.
- Action
- Update libnet-dns-perl to the patched version from DSA-6459-1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-64193
Get an email if CVE-2026-64193 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.83% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownDSA-6459-1 libnet-dns-perl - security updatedebian · 2026-08-22
- criticalCVE-2026-64193: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERR…nvd · 2026-07-20
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-64193)