cpan
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 26 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 31, 2004 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID
Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
CVE-2026-57075: YAML::Syck versions befo1.47 for Perl allow an out-of-bounds ad via a signed-char lookup-table index in syck_base64dec
Important: perl-XML-LibXML security update
Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol
Monitor cpan in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.