SecAlerts
Perl logo

Perl

Security Risk Profile

58
/100
medium

Security Risk Score

Comprehensive risk assessment based on 197 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 31, 1999 to present

197
Total CVEs
79
Critical+High
1
Exploited
31
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
31
Critical/High
Risk Level
58/100
medium
⚠️ 1 Active Exploits🆕 8Fresh (<7d)📈 16 in Last 30 Days

Severity Distribution

Critical
27
High
52
Medium
49
Low
11

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
Buffer Overflow
38
2
Integer Overflow
10
3
Input Validation
9
4
Race Condition
6
5
Weak RNG
5

Most Affected Products

1. Perl Perl860
2. Dan Kogai Encode Module118
3. Mark Stosberg Data\72
4. Perl pcre52
5. Canonical Ubuntu Linux50

Recent Vulnerabilities

See more →
CVE-2026-15689
unknown

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send

8/15/2026🔧 No Patch
CVE-2026-13048
CVSS 8.2high

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename

8/13/2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/480
unknown

CVE-2026-19487: Perl versions from 5.9.4 befo5.41.9 produce incorct gular expssion match sults when a stale failuflag ends the Aho-Corasick pscan early in S_find_byclass

8/13/2026🔧 No Patch
CVE-2026-19487
CVSS 5.3medium

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass

8/13/2026🔧 No Patch
REDHAT-BUG-2513963
CVSS 7.0high
8/11/2026🔧 No Patch
CVE-2026-15534
CVSS 5.7medium

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch

8/9/2026🔧 No Patch
CVE-2026-17510
CVSS 7.5high

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute

8/9/2026🔧 No Patch
RHSA-2026:49523
unknown

Important: perl-Archive-Tar security update

8/3/2026🔧 No Patch
CVE-2026-59145
CVSS 9.1critical

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find

7/21/2026🔧 No Patch
CVE-2026-59144
CVSS 9.8critical

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq

7/21/2026🔧 No Patch

Monitor Perl in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Perl Security Vulnerabilities & Risk Score | 197 CVEs | SecAlerts - SecAlerts