Date Index - July 2026 - CPANSec CVE announcements

01 Jul 2026 06:47 UTC CVE-2026-56016: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources Robert Rothenberg
01 Jul 2026 14:40 UTC CVE-2025-15646: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion Robert Rothenberg
03 Jul 2026 12:57 UTC CVE-2026-56015: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length Robert Rothenberg
04 Jul 2026 17:55 UTC CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg
04 Jul 2026 17:59 UTC CVE-2026-12740: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg
05 Jul 2026 01:33 UTC CVE-2026-14570: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery Timothy Legge
06 Jul 2026 01:39 UTC CVE-2026-14803: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder Stig Palmquist
06 Jul 2026 12:06 UTC CVE-2026-13705: Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle Stig Palmquist
06 Jul 2026 12:07 UTC CVE-2026-13708: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol Stig Palmquist
07 Jul 2026 11:47 UTC CVE-2011-10043: Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded Robert Rothenberg
07 Jul 2026 17:43 UTC CVE-2026-7017: HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets Robert Rothenberg
07 Jul 2026 22:06 UTC CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Robert Rothenberg
07 Jul 2026 22:07 UTC DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders Robert Rothenberg
07 Jul 2026 22:08 UTC CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Robert Rothenberg
07 Jul 2026 22:13 UTC CVE-2026-14895: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service Robert Rothenberg
08 Jul 2026 12:31 UTC CVE-2026-14454: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed Robert Rothenberg
08 Jul 2026 14:58 UTC CVE-2026-49145: App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc Stig Palmquist
08 Jul 2026 14:59 UTC CVE-2026-49146: App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc Stig Palmquist
08 Jul 2026 15:00 UTC CVE-2026-49147: App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes Stig Palmquist
13 Jul 2026 15:43 UTC CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk Stig Palmquist
13 Jul 2026 15:46 UTC CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack Stig Palmquist
13 Jul 2026 15:51 UTC CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record Stig Palmquist
13 Jul 2026 22:25 UTC CVE-2026-58101: Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference Timothy Legge
13 Jul 2026 22:25 UTC CVE-2026-58102: Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts Timothy Legge
14 Jul 2026 09:45 UTC CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text Robert Rothenberg
14 Jul 2026 15:36 UTC CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row Robert Rothenberg
14 Jul 2026 15:39 UTC CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index Robert Rothenberg
14 Jul 2026 15:39 UTC CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location Robert Rothenberg
14 Jul 2026 17:11 UTC CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle Stig Palmquist
16 Jul 2026 16:16 UTC CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead Robert Rothenberg
16 Jul 2026 16:17 UTC CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg
16 Jul 2026 16:18 UTC CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead Robert Rothenberg
16 Jul 2026 16:18 UTC CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg
16 Jul 2026 16:23 UTC CVE-2026-3031: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library Robert Rothenberg