Skip to main content

Vendor archive

perl CVEs

Beta · best-effort

75 CVEs tagged to vendor perl17 Critical, 29 High, 26 Medium, 3 Low, 0 Unrated.

CVE-2026-57432

Published Jul 13, 2026

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times…

CVSS 8.4 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-13221

Published Jul 13, 2026

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_stu…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-14740

Published Jul 7, 2026

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-14739

Published Jul 7, 2026

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-14380

Published Jul 7, 2026

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it in…

CVSS 8.8 · High
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-9698

Published Jun 9, 2026

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
43.5
Vendor/product tagsBeta · best-effort

CVE-2026-10879

Published Jun 5, 2026

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbere…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
35.9
Vendor/product tagsBeta · best-effort

CVE-2026-8376

Published May 26, 2026

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c ch…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-4176

Published Mar 29, 2026

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is i…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2024-56406

Published Apr 13, 2025

A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, including development versions from 5.33.1 through 5.41.10.…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47039

Published Jan 2, 2024

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48522

Published Aug 22, 2023

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31486

Published Apr 29, 2023

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10402

Published Sep 16, 2020

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10401

Published Sep 11, 2020

An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7491

Published Sep 11, 2020

An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack ge…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7490

Published Sep 11, 2020

An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 75 CVEsPage 1 of 3