Perl
Perl · 48 CVEs
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect r…
Jul 13, 2026
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in…
Jul 13, 2026
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow…
May 25, 2026
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerab…
Mar 29, 2026
Perl threads have a working directory race condition where file operations may target unintended paths
May 30, 2025
Perl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytes
Apr 13, 2025
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, w…
Mar 18, 2024
Perl: perl for windows binary hijacking vulnerability
Jan 2, 2024
Perl: write past buffer end via illegal user-defined unicode property
Dec 18, 2023
perl: stack-based crash in S_find_uninit_var()
Aug 22, 2023
http-tiny: perl: insecure TLS cert default
Apr 28, 2023
perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS
Apr 28, 2023
perl: corruption of intermediate language state of compiled regular expression due to recursive S_study_chunk() calls l…
Jun 5, 2020
perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
Jun 5, 2020
perl: heap-based buffer overflow in regular expression compiler leads to DoS
Jun 5, 2020
perl: Heap-based buffer overflow in S_regatom()
Dec 7, 2018
perl: Heap-based buffer read overflow in S_grok_bslash_N()
Dec 7, 2018
perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
Dec 7, 2018
perl: Heap-based buffer overflow in S_handle_regex_sets()
Dec 5, 2018
perl: Directory traversal in Archive::Tar
Jun 7, 2018
perl: heap buffer overflow in pp_pack.c
Apr 17, 2018
perl: heap read overflow in regexec.c
Apr 17, 2018
perl: heap write overflow in regcomp.c
Apr 17, 2018
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x befor…
Sep 27, 2017
perl: Buffer over-read in regular expression parser
Sep 19, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-13221 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an altern… | CRITICAL | 0.43% | Jul 13, 2026 |
| CVE-2026-57432 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bo… | HIGH | 0.21% | Jul 13, 2026 |
| CVE-2026-8376 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with… | CRITICAL | 0.48% | May 25, 2026 |
| CVE-2026-4176 | Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib | CRITICAL | 0.81% | Mar 29, 2026 |
| CVE-2025-40909 | Perl threads have a working directory race condition where file operations may target unintended paths | MEDIUM | 0.50% | May 30, 2025 |
| CVE-2024-56406 | Perl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytes | HIGH | 0.54% | Apr 13, 2025 |
| CVE-2021-47155 | The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attacke… | CRITICAL | 0.51% | Mar 18, 2024 |
| CVE-2023-47039 | Perl: perl for windows binary hijacking vulnerability | HIGH | 0.42% | Jan 2, 2024 |
| CVE-2023-47038 | Perl: write past buffer end via illegal user-defined unicode property | HIGH | 0.81% | Dec 18, 2023 |
| CVE-2022-48522 | perl: stack-based crash in S_find_uninit_var() | CRITICAL | 2.61% | Aug 22, 2023 |
| CVE-2023-31486 | http-tiny: perl: insecure TLS cert default | HIGH | 1.74% | Apr 28, 2023 |
| CVE-2023-31484 | perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS | HIGH | 1.55% | Apr 28, 2023 |
| CVE-2020-12723 | perl: corruption of intermediate language state of compiled regular expression due to recursive S_study_chunk() calls leads to DoS | HIGH | 5.97% | Jun 5, 2020 |
| CVE-2020-10878 | perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS | HIGH | 4.88% | Jun 5, 2020 |
| CVE-2020-10543 | perl: heap-based buffer overflow in regular expression compiler leads to DoS | HIGH | 11.33% | Jun 5, 2020 |
| CVE-2018-18314 | perl: Heap-based buffer overflow in S_regatom() | CRITICAL | 6.06% | Dec 7, 2018 |
| CVE-2018-18313 | perl: Heap-based buffer read overflow in S_grok_bslash_N() | CRITICAL | 9.52% | Dec 7, 2018 |
| CVE-2018-18311 | perl: Integer overflow leading to buffer overflow in Perl_my_setenv() | CRITICAL | 11.68% | Dec 7, 2018 |
| CVE-2018-18312 | perl: Heap-based buffer overflow in S_handle_regex_sets() | CRITICAL | 12.09% | Dec 5, 2018 |
| CVE-2018-12015 | perl: Directory traversal in Archive::Tar | HIGH | 7.31% | Jun 7, 2018 |
| CVE-2018-6913 | perl: heap buffer overflow in pp_pack.c | CRITICAL | 10.67% | Apr 17, 2018 |
| CVE-2018-6798 | perl: heap read overflow in regexec.c | HIGH | 3.93% | Apr 17, 2018 |
| CVE-2018-6797 | perl: heap write overflow in regcomp.c | CRITICAL | 6.48% | Apr 17, 2018 |
| CVE-2017-12814 | Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers… | CRITICAL | 6.98% | Sep 27, 2017 |
| CVE-2017-12883 | perl: Buffer over-read in regular expression parser | CRITICAL | 5.91% | Sep 19, 2017 |
Showing 1 to 25 of 48 CVEs