Fedora 43 and 44 Vulnerability in perl-URI IDNA Normalization

Fedora 43 and 44 Vulnerability in perl-URI IDNA Normalization

First seen 25 Aug 2026, 10:17 UTC Linuxsecurity 30.9

Article Content

Browse articles
ThreatCluster

Fedora 43 and 44 face a significant vulnerability related to IDNA normalization in the perl-URI module, identified as CVE-2026-19953. This issue affects the handling of Unicode NFC normalization, leading to potential discrepancies in IDNA host encoding. The vulnerability was patched on August 21, 2026, by Jitka Plesnikova, with the release of perl-URI version 5.36-1. Users are advised to upgrade their systems using the 'dnf' update program to mitigate the risk. The flaw could allow for non-standard A-label emissions, which may impact interoperability with other clients. The updates are available for installation, and users should apply them promptly to ensure system security.

Key Points: • CVE-2026-19953 affects Fedora 43 and 44 due to IDNA normalization issues. • The vulnerability was patched on August 21, 2026, with perl-URI version 5.36-1. • Users must upgrade using 'dnf' to mitigate potential security risks.

Timeline

2026-08-21
Patch released for CVE-2026-19953
Fedora released perl-URI version 5.36-1 to address IDNA normalization issues affecting host encoding.
Linuxsecurity
2026-08-23
Fedora 44 perl-URI update announced
An update for perl-URI in Fedora 44 was published, addressing the same IDNA normalization vulnerability.
Linuxsecurity
2026-08-25
Current status of the vulnerability
As of today, users are urged to apply the updates to mitigate the risk associated with CVE-2026-19953.
Linuxsecurity