Perl
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 201 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 31, 1999 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
CVE-2026-19487: Perl versions from 5.9.4 befo5.41.9 produce incorct gular expssion match sults when a stale failuflag ends the Aho-Corasick pscan early in S_find_byclass
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute
Important: perl-Archive-Tar security update
Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time
Monitor Perl in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.