login
login
Home
CPANSec CVE announcements
Archive index August 2026
Thread Index - August 2026 - CPANSec CVE announcements
Search:
Search
« July
Archive index
By date
Refresh
September »
CVE-2026-18536: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
Robert Rothenberg
(01 Aug 2026 10:38 UTC)
CVE-2026-18089: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured
Timothy Legge
(03 Aug 2026 12:44 UTC)
CVE-2026-18108: Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature
Timothy Legge
(03 Aug 2026 13:05 UTC)
CVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
Timothy Legge
(03 Aug 2026 13:11 UTC)
CVE-2026-18092: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree
Timothy Legge
(03 Aug 2026 13:26 UTC)
CVE-2026-9487: XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID
Timothy Legge
(03 Aug 2026 13:42 UTC)
CVE-2026-18568: XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check
Timothy Legge
(03 Aug 2026 14:40 UTC)
CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
Robert Rothenberg
(04 Aug 2026 20:50 UTC)
CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
Robert Rothenberg
(04 Aug 2026 20:52 UTC)
CVE-2026-19082: Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
Stig Palmquist
(07 Aug 2026 17:59 UTC)
CVE-2026-17435: File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
Robert Rothenberg
(07 Aug 2026 19:04 UTC)
CVE-2026-17510: Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute
Timothy Legge
(09 Aug 2026 01:27 UTC)
CVE-2026-15534: Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Stig Palmquist
(09 Aug 2026 17:52 UTC)
CVE-2026-19566: Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths
Robert Rothenberg
(12 Aug 2026 08:41 UTC)
CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
Robert Rothenberg
(12 Aug 2026 23:15 UTC)
CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
Robert Rothenberg
(12 Aug 2026 23:18 UTC)
CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
Stig Palmquist
(13 Aug 2026 15:54 UTC)
CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template
Robert Rothenberg
(13 Aug 2026 16:30 UTC)
CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
Robert Rothenberg
(13 Aug 2026 16:31 UTC)
CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template
Robert Rothenberg
(13 Aug 2026 16:31 UTC)
CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse
Robert Rothenberg
(15 Aug 2026 12:10 UTC)
CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse
Robert Rothenberg
(15 Aug 2026 12:11 UTC)
CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
Timothy Legge
(15 Aug 2026 13:27 UTC)
CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
Timothy Legge
(16 Aug 2026 13:24 UTC)
CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
Robert Rothenberg
(16 Aug 2026 13:51 UTC)
CVE-2026-72888: Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require
Robert Rothenberg
(16 Aug 2026 13:52 UTC)
CVE-2026-72889: Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
Robert Rothenberg
(19 Aug 2026 07:23 UTC)
CVE-2026-75589: Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify
Robert Rothenberg
(19 Aug 2026 07:24 UTC)
CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter
Timothy Legge
(20 Aug 2026 00:43 UTC)
CVE-2026-15743: Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable
Robert Rothenberg
(20 Aug 2026 18:16 UTC)
CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Robert Rothenberg
(21 Aug 2026 23:59 UTC)
CVE-2026-75870: Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret
Timothy Legge
(22 Aug 2026 13:37 UTC)
CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them
Timothy Legge
(22 Aug 2026 13:54 UTC)
CVE-2026-75922: Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line
Timothy Legge
(23 Aug 2026 18:21 UTC)
CVE-2026-19565: Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
Robert Rothenberg
(23 Aug 2026 19:19 UTC)
CVE-2026-78183: DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float
Robert Rothenberg
(23 Aug 2026 19:55 UTC)
CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
Timothy Legge
(25 Aug 2026 21:22 UTC)
CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
Timothy Legge
(25 Aug 2026 21:25 UTC)
CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements
Robert Rothenberg
(31 Aug 2026 10:08 UTC)
CVE-2026-19953: URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
Robert Rothenberg
(31 Aug 2026 17:31 UTC)