login
login
Home
CPANSec CVE announcements
Archive index July 2026
Date Index - July 2026 - CPANSec CVE announcements
Search:
Search
« June
Archive index
By threads
Refresh
August »
01 Jul 2026 06:47 UTC
CVE-2026-56016: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
Robert Rothenberg
01 Jul 2026 14:40 UTC
CVE-2025-15646: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion
Robert Rothenberg
03 Jul 2026 12:57 UTC
CVE-2026-56015: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length
Robert Rothenberg
04 Jul 2026 17:55 UTC
CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter
Robert Rothenberg
04 Jul 2026 17:59 UTC
CVE-2026-12740: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter
Robert Rothenberg
05 Jul 2026 01:33 UTC
CVE-2026-14570: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
Timothy Legge
06 Jul 2026 01:39 UTC
CVE-2026-14803: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder
Stig Palmquist
06 Jul 2026 12:06 UTC
CVE-2026-13705: Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
Stig Palmquist
06 Jul 2026 12:07 UTC
CVE-2026-13708: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol
Stig Palmquist
07 Jul 2026 11:47 UTC
CVE-2011-10043: Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded
Robert Rothenberg
07 Jul 2026 17:43 UTC
CVE-2026-7017: HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
Robert Rothenberg
07 Jul 2026 22:06 UTC
CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Robert Rothenberg
07 Jul 2026 22:07 UTC
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
Robert Rothenberg
07 Jul 2026 22:08 UTC
CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Robert Rothenberg
07 Jul 2026 22:13 UTC
CVE-2026-14895: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
Robert Rothenberg
08 Jul 2026 12:31 UTC
CVE-2026-14454: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
Robert Rothenberg
08 Jul 2026 14:58 UTC
CVE-2026-49145: App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc
Stig Palmquist
08 Jul 2026 14:59 UTC
CVE-2026-49146: App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc
Stig Palmquist
08 Jul 2026 15:00 UTC
CVE-2026-49147: App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
Stig Palmquist
13 Jul 2026 15:43 UTC
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
Stig Palmquist
13 Jul 2026 15:46 UTC
CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Stig Palmquist
13 Jul 2026 15:51 UTC
CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Stig Palmquist
13 Jul 2026 22:25 UTC
CVE-2026-58101: Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference
Timothy Legge
13 Jul 2026 22:25 UTC
CVE-2026-58102: Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts
Timothy Legge
14 Jul 2026 09:45 UTC
CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
Robert Rothenberg
14 Jul 2026 15:36 UTC
CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Robert Rothenberg
14 Jul 2026 15:39 UTC
CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index
Robert Rothenberg
14 Jul 2026 15:39 UTC
CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Robert Rothenberg
14 Jul 2026 17:11 UTC
CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
Stig Palmquist
16 Jul 2026 16:16 UTC
CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead
Robert Rothenberg
16 Jul 2026 16:17 UTC
CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
16 Jul 2026 16:18 UTC
CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead
Robert Rothenberg
16 Jul 2026 16:18 UTC
CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
16 Jul 2026 16:23 UTC
CVE-2026-3031: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
Robert Rothenberg
16 Jul 2026 22:02 UTC
CVE-2026-13713: YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack
Paul Johnson
16 Jul 2026 22:04 UTC
CVE-2026-57075: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec
Paul Johnson
16 Jul 2026 22:05 UTC
CVE-2026-57076: YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor
Paul Johnson
16 Jul 2026 22:06 UTC
CVE-2026-57077: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len
Paul Johnson
17 Jul 2026 12:51 UTC
CVE-2026-13410: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
Robert Rothenberg
17 Jul 2026 12:55 UTC
CVE-2026-13082: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
Robert Rothenberg
17 Jul 2026 15:21 UTC
CVE-2026-14741: HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
Robert Rothenberg
17 Jul 2026 15:31 UTC
CVE-2026-9537: Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison
Robert Rothenberg
20 Jul 2026 07:04 UTC
CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts
Robert Rothenberg
20 Jul 2026 07:05 UTC
CVE-2026-6656: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
Robert Rothenberg
20 Jul 2026 07:12 UTC
CVE-2026-13577: Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable
Robert Rothenberg
20 Jul 2026 17:56 UTC
CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains
Robert Rothenberg
20 Jul 2026 17:56 UTC
CVE-2026-64193: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR
Robert Rothenberg
21 Jul 2026 19:14 UTC
CVE-2026-65069: Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:15 UTC
CVE-2026-65068: Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:16 UTC
CVE-2026-65067: Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:16 UTC
CVE-2026-65066: Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:18 UTC
CVE-2026-65065: Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:18 UTC
CVE-2026-65064: Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:19 UTC
CVE-2026-65063: Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:19 UTC
CVE-2026-65062: Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:20 UTC
CVE-2026-65061: Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:21 UTC
CVE-2026-64617: Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:22 UTC
CVE-2026-64616: Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:23 UTC
CVE-2026-64615: Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:24 UTC
CVE-2026-64614: Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:24 UTC
CVE-2026-64613: Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW
Robert Rothenberg
21 Jul 2026 19:25 UTC
CVE-2026-59147: Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find
Robert Rothenberg
21 Jul 2026 19:26 UTC
CVE-2026-59146: Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot
Robert Rothenberg
21 Jul 2026 19:26 UTC
CVE-2026-59145: Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find
Robert Rothenberg
21 Jul 2026 19:27 UTC
CVE-2026-59144: Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq
Robert Rothenberg
21 Jul 2026 19:28 UTC
CVE-2026-59143: Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked
Robert Rothenberg
21 Jul 2026 19:28 UTC
CVE-2026-59142: Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy
Robert Rothenberg
21 Jul 2026 19:29 UTC
CVE-2026-59141: Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked
Robert Rothenberg
21 Jul 2026 19:29 UTC
CVE-2026-59140: Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths
Robert Rothenberg
21 Jul 2026 19:30 UTC
CVE-2026-59139: Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked
Robert Rothenberg
22 Jul 2026 20:32 UTC
CVE-2026-13089: OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify
Robert Rothenberg
24 Jul 2026 09:16 UTC
CVE-2026-16634: TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
Robert Rothenberg
24 Jul 2026 15:03 UTC
CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp
Robert Rothenberg
25 Jul 2026 08:13 UTC
CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
Robert Rothenberg
27 Jul 2026 18:11 UTC
CVE-2026-17552: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call
Robert Rothenberg
30 Jul 2026 13:43 UTC
CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check
Robert Rothenberg
30 Jul 2026 13:44 UTC
CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time
Robert Rothenberg