Skip to main content

Vendor/product archive

perl / perl CVEs

Beta · best-effort

56 CVEs tagged to perl / perl13 Critical, 24 High, 17 Medium, 2 Low, 0 Unrated.

CVE-2026-57432

Published Jul 13, 2026

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times…

CVSS 8.4 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-13221

Published Jul 13, 2026

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_stu…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-8376

Published May 26, 2026

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c ch…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-4176

Published Mar 29, 2026

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is i…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2024-56406

Published Apr 13, 2025

A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, including development versions from 5.33.1 through 5.41.10.…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47039

Published Jan 2, 2024

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48522

Published Aug 22, 2023

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31486

Published Apr 29, 2023

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12814

Published Sep 28, 2017

Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12883

Published Sep 19, 2017

Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12837

Published Sep 19, 2017

Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (ou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 56 CVEsPage 1 of 3