Perl

Perl

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 05.10.2026 06:50:17
  • Zuletzt bearbeitet 06.10.2026 17:17:09

YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing r...

  • EPSS 0.18%
  • Veröffentlicht 05.10.2026 06:49:17
  • Zuletzt bearbeitet 06.10.2026 17:17:08

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it go...

  • EPSS 0.4%
  • Veröffentlicht 22.09.2026 07:25:37
  • Zuletzt bearbeitet 22.09.2026 19:07:00

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed ...

  • EPSS -
  • Veröffentlicht 20.08.2026 18:15:26
  • Zuletzt bearbeitet 28.08.2026 16:17:07

Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content m...

  • EPSS 0.2%
  • Veröffentlicht 15.08.2026 12:09:03
  • Zuletzt bearbeitet 28.08.2026 15:42:20

DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seve...

  • EPSS 0.43%
  • Veröffentlicht 13.08.2026 15:51:04
  • Zuletzt bearbeitet 28.08.2026 15:42:20

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match...

  • EPSS 0.43%
  • Veröffentlicht 13.07.2026 15:40:11
  • Zuletzt bearbeitet 08.09.2026 22:17:37

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk....

  • EPSS 0.21%
  • Veröffentlicht 13.07.2026 15:38:20
  • Zuletzt bearbeitet 08.09.2026 22:18:30

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat...

  • EPSS 0.44%
  • Veröffentlicht 25.05.2026 23:53:27
  • Zuletzt bearbeitet 08.09.2026 22:19:18

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the ...

  • EPSS 0.68%
  • Veröffentlicht 29.03.2026 20:50:51
  • Zuletzt bearbeitet 22.04.2026 17:31:45

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerab...