-Infinity
0

Perl Data::Intern::SharedData::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find

Risk 66
Severity
9.1
First published (updated )

Perl Data::RingBuffer::SharedData::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq

Risk 86
Severity
9.8
First published (updated )

Perl Net::DNSNet::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR

Risk 90
Severity
9.8
First published (updated )

Perl HTTP::DateHTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date

Risk 46
Severity
7.5
First published (updated )

oss-secCVE-2026-57076: YAML::Syck versions befo1.47 for Perl allow a heap use-after-fe via an anchor name used as an anchors-table key in syck_hdlr_add_anchor

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Perl YAML::SyckYAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor

Risk 73
Severity
7.8
First published (updated )

Perl HTML::BareHTML::Bare versions through 0.04 for Perl have an unbounded character lookahead

Risk 70
Severity
9.1
First published (updated )

Perl HTML::BareHTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes

Risk 46
Severity
7.5
First published (updated )

Perl DBIDBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

Risk 70
Severity
9.1
First published (updated )

Perl DBI::ProfileDataDBI::ProfileData versions before 1.651 for Perl do not limit the path index

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Perl DBD::FileDBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location

Risk 60
Severity
7.7
First published (updated )

oss-secCVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measu_struct leading to an out-of-bounds heap ad in pack and unpack

oss-secCVE-2026-13221: Perl versions through 5.43.9 produce silently incorct gular expssion matches when an alternation of mothan 65535 fixed string branches is compiled into a trie in Perl_study_chunk

Perl PerlPerl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk

Risk 70
Severity
9.1
First published (updated )

Perl PerlPerl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack

Risk 79
Severity
8.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Perl String::UtilString::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service

Risk 46
Severity
7.5
First published (updated )

Perl DBIDBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment

Risk 70
Severity
9.1
First published (updated )

Perl DBI DBIDBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders

Risk 86
Severity
9.8
First published (updated )

DBI DBIDBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile

Risk 84
Severity
8.8
First published (updated )

Perl Module::LoadModule::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Perl Net::IP::LPMNet::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length

Risk 70
Severity
9.1
First published (updated )

Perl CGI::Session::ID::md5CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources

Risk 37
Severity
5.9
First published (updated )

Perl Net::BitTorrentNet::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG

Risk 37
Severity
5.9
First published (updated )

Perl JavaScript::Minifier::XSJavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash

Risk 46
Severity
7.5
First published (updated )

Perl List::SomeUtils::XSList::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Perl IO-CompressImportant: perl-IO-Compress security update

Risk 77
First published (updated )

oss-secProposal: Add separate oss-security-vulnerability-ports mailing list (for AI vulnpocalypse)

cpan/DBIDBI versions before 1.648 for Perl saved errors in a limited-sized buffer

Risk 63
Severity
9.8
EPSS
0.45%
First published (updated )

cpan/DBIDBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders

Risk 91
Severity
9.8
First published (updated )

Perl Archive::TarArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203