oss-security·2d agoCVE-2026-95811: Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it#lemonldap-ng#perl#cve-2026-95811CVE-2026-95811 3 sources
oss-security·2d ago highRe: CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL#cpan#perl#supply-chainCVE-2026-95831 4 sources in the wild
oss-security·2d agoCVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone#perl#catalyst#authorization-bypassCVE-2026-85491 2 sources
oss-security·4d agoCVE-2026-74766: Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode#perl#punycode#cve-2026-74766CVE-2026-74766 8 sources
oss-security·5d agoCVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler#cve-2026-93712#dancer2#perlCVE-2026-93712 4 sources
oss-security·5d agoCVE-2026-93012: Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe#perl#email-sender#command-injectionCVE-2026-93012
oss-security·7d agoCVE-2026-82560: Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width#denial-of-service#oss-security#perlCVE-2026-82560
oss-security·7d agoCVE-2026-78030: DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM#arbitrary-module-loading#cve-2026-78030#dbd-dbmCVE-2026-780301
oss-security·8d agoCVE-2026-93019: Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read#cve-2026-93019#denial-of-service#image-processingCVE-2026-93019 2 sources
oss-security·9d agoCVE-2026-73639: Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8#buffer-overflow#cve#image-parsingCVE-2026-73639 2 sources
Ubuntu Security Notices·10d agoUSN-8736-2: Perl vulnerabilities#denial-of-service#perl#regexCVE-2026-155341
Ubuntu Security Notices·17d agoUSN-8675-2: Perl vulnerabilities#information-disclosure#patch#perlCVE-2026-12087
oss-security·18d agoCVE-2026-85485: HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping#cve-2026-85485#html-formhandler#input-validationCVE-2026-85485 2 sources1
oss-security·18d agoCVE-2026-19872: HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message#cve-2026-19872#html-formhandler#oss-securityCVE-2026-19872 2 sources
Ubuntu Security Notices·18d agoUSN-8736-1: Perl vulnerabilities#canonical#denial-of-service#patchCVE-2026-15534
oss-security·19d agoCVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table#cve-2026-16028#dos#http2CVE-2026-16028
oss-security·19d agoCVE-2026-86287: Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths#cve-2026-86287#input-validation#longest-prefix-matchCVE-2026-86287
oss-security·20d agoCVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor#authentication-bypass#mojox-authentication#net-saml2CVE-2026-86304
oss-security·20d agoCVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step#authentication#digest-md5#perlCVE-2026-862191
Palo Alto Unit 42·Aug 19, 2026Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self#botnet#cryptomining#defense-evasion in the wild 6 min