login
login
Home
CPANSec CVE announcements
Archive index August 2026
Date Index - August 2026 - CPANSec CVE announcements
Search:
Search
« July
Archive index
By threads
Refresh
September »
01 Aug 2026 10:38 UTC
CVE-2026-18536: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
Robert Rothenberg
03 Aug 2026 12:44 UTC
CVE-2026-18089: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured
Timothy Legge
03 Aug 2026 13:05 UTC
CVE-2026-18108: Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature
Timothy Legge
03 Aug 2026 13:11 UTC
CVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
Timothy Legge
03 Aug 2026 13:26 UTC
CVE-2026-18092: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree
Timothy Legge
03 Aug 2026 13:42 UTC
CVE-2026-9487: XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID
Timothy Legge
03 Aug 2026 14:40 UTC
CVE-2026-18568: XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check
Timothy Legge
04 Aug 2026 20:50 UTC
CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
Robert Rothenberg
04 Aug 2026 20:52 UTC
CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
Robert Rothenberg
07 Aug 2026 17:59 UTC
CVE-2026-19082: Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
Stig Palmquist
07 Aug 2026 19:04 UTC
CVE-2026-17435: File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
Robert Rothenberg
09 Aug 2026 01:27 UTC
CVE-2026-17510: Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute
Timothy Legge
09 Aug 2026 17:52 UTC
CVE-2026-15534: Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Stig Palmquist
12 Aug 2026 08:41 UTC
CVE-2026-19566: Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths
Robert Rothenberg
12 Aug 2026 23:15 UTC
CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
Robert Rothenberg
12 Aug 2026 23:18 UTC
CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
Robert Rothenberg
13 Aug 2026 15:54 UTC
CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
Stig Palmquist
13 Aug 2026 16:30 UTC
CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template
Robert Rothenberg
13 Aug 2026 16:31 UTC
CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
Robert Rothenberg
13 Aug 2026 16:31 UTC
CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template
Robert Rothenberg