Back

CRITICAL

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99

Published Jul 24, 2026

Description

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.

The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker.

Any caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document.

TOML::XS version 0.06 or later uses the successor tomlc17 library.

Affected products

Remediation

Vendor solution

Upgrade to TOML::XS version 0.06 or later.

Metrics

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Jul 24, 2026
Updated Jul 27, 2026
Reserved Jul 22, 2026
CISA Vulnrichment
Updated Jul 27, 2026
NVD
Status Deferred
Modified Jul 27, 2026
Red Hat
Severity n/a
Public date n/a