SecAlerts
Perl logo

Perl

Security Risk Profile

63
/100
high

Security Risk Score

Comprehensive risk assessment based on 184 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 31, 1999 to present

184
Total CVEs
73
Critical+High
1
Exploited
24
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
24
Critical/High
Risk Level
63/100
high
⚠️ 1 Active Exploits🆕 4Fresh (<7d)📈 25 in Last 30 Days

Severity Distribution

Critical
27
High
46
Medium
47
Low
11

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
Buffer Overflow
38
2
Integer Overflow
9
3
Input Validation
9
4
Race Condition
6
5
Weak RNG
5

Most Affected Products

1. Perl Perl856
2. Dan Kogai Encode Module118
3. Mark Stosberg Data\72
4. Perl pcre52
5. Canonical Ubuntu Linux50

Recent Vulnerabilities

See more →
CVE-2026-59145
CVSS 9.1critical

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find

7/21/2026🔧 No Patch
CVE-2026-59144
CVSS 9.8critical

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq

7/21/2026🔧 No Patch
CVE-2026-64193
CVSS 9.8critical

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR

7/20/2026🔧 No Patch
CVE-2026-14741
CVSS 7.5high

HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date

7/17/2026
https://seclists.org/oss-sec/2026/q3/160
unknown

CVE-2026-57076: YAML::Syck versions befo1.47 for Perl allow a heap use-after-fe via an anchor name used as an anchors-table key in syck_hdlr_add_anchor

7/16/2026🔧 No Patch
CVE-2026-57076
CVSS 7.8high

YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor

7/16/2026🔧 No Patch
CVE-2026-57073
CVSS 9.1critical

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead

7/16/2026🔧 No Patch
CVE-2026-13397
CVSS 7.5high

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes

7/16/2026🔧 No Patch
CVE-2026-60082
CVSS 9.1critical

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

7/14/2026
CVE-2026-60081
CVSS 7.5high

DBI::ProfileData versions before 1.651 for Perl do not limit the path index

7/14/2026

Monitor Perl in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.