login
login
Home
CPANSec CVE announcements
Archive index July 2026
Thread Index - July 2026 - CPANSec CVE announcements
Search:
Search
« June
Archive index
By date
Refresh
August »
CVE-2026-56016: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
Robert Rothenberg
(01 Jul 2026 06:47 UTC)
CVE-2025-15646: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion
Robert Rothenberg
(01 Jul 2026 14:40 UTC)
CVE-2026-56015: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length
Robert Rothenberg
(03 Jul 2026 12:57 UTC)
CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter
Robert Rothenberg
(04 Jul 2026 17:55 UTC)
CVE-2026-12740: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter
Robert Rothenberg
(04 Jul 2026 17:59 UTC)
CVE-2026-14570: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
Timothy Legge
(05 Jul 2026 01:33 UTC)
CVE-2026-14803: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder
Stig Palmquist
(06 Jul 2026 01:39 UTC)
CVE-2026-13705: Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
Stig Palmquist
(06 Jul 2026 12:06 UTC)
CVE-2026-13708: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol
Stig Palmquist
(06 Jul 2026 12:07 UTC)
CVE-2011-10043: Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded
Robert Rothenberg
(07 Jul 2026 11:47 UTC)
CVE-2026-7017: HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
Robert Rothenberg
(07 Jul 2026 17:43 UTC)
CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Robert Rothenberg
(07 Jul 2026 22:06 UTC)
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
Robert Rothenberg
(07 Jul 2026 22:07 UTC)
CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Robert Rothenberg
(07 Jul 2026 22:08 UTC)
CVE-2026-14895: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
Robert Rothenberg
(07 Jul 2026 22:13 UTC)
CVE-2026-14454: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
Robert Rothenberg
(08 Jul 2026 12:31 UTC)
CVE-2026-49145: App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc
Stig Palmquist
(08 Jul 2026 14:58 UTC)
CVE-2026-49146: App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc
Stig Palmquist
(08 Jul 2026 14:59 UTC)
CVE-2026-49147: App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
Stig Palmquist
(08 Jul 2026 15:00 UTC)
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
Stig Palmquist
(13 Jul 2026 15:43 UTC)
CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Stig Palmquist
(13 Jul 2026 15:46 UTC)
CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Stig Palmquist
(13 Jul 2026 15:51 UTC)
CVE-2026-58101: Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference
Timothy Legge
(13 Jul 2026 22:25 UTC)
CVE-2026-58102: Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts
Timothy Legge
(13 Jul 2026 22:25 UTC)
CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
Robert Rothenberg
(14 Jul 2026 09:45 UTC)
CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Robert Rothenberg
(14 Jul 2026 15:36 UTC)
CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index
Robert Rothenberg
(14 Jul 2026 15:39 UTC)
CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Robert Rothenberg
(14 Jul 2026 15:39 UTC)
CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
Stig Palmquist
(14 Jul 2026 17:11 UTC)
CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead
Robert Rothenberg
(16 Jul 2026 16:16 UTC)
CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
(16 Jul 2026 16:17 UTC)
CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead
Robert Rothenberg
(16 Jul 2026 16:18 UTC)
CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
(16 Jul 2026 16:18 UTC)
CVE-2026-3031: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
Robert Rothenberg
(16 Jul 2026 16:23 UTC)