SecAlerts
P

Perl

Security Risk Profile

56
/100
medium

Security Risk Score

Comprehensive risk assessment based on 211 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 31, 1999 to present

211
Total CVEs
87
Critical+High
1
Exploited
39
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
39
Critical/High
Risk Level
56/100
medium
⚠️ 1 Active Exploits🆕 8Fresh (<7d)📈 13 in Last 30 Days

Severity Distribution

Critical
29
High
58
Medium
52
Low
11

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
Buffer Overflow
38
2
Integer Overflow
10
3
Input Validation
9
4
Race Condition
6
5
Weak RNG
5

Most Affected Products

1. Perl Perl864
2. Dan Kogai Encode Module118
3. Mark Stosberg Data\72
4. Perl pcre52
5. Canonical Ubuntu Linux50

Recent Vulnerabilities

See more →
CVE-2026-93012
CVSS 9.8critical

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe

Sep 21, 2026🔧 No Patch
CVE-2026-82560
CVSS 7.5high

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width

Sep 19, 2026🔧 No Patch
CVE-2026-78030
CVSS 9.8critical

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM

Sep 19, 2026🔧 No Patch
CVE-2026-85484
CVSS 6.1medium

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping

Sep 8, 2026🔧 No Patch
CVE-2026-16028
CVSS 7.5high

Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table

Sep 7, 2026🔧 No Patch
CVE-2026-86287
CVSS 7.5high

Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths

Sep 7, 2026🔧 No Patch
CVE-2026-86304
CVSS 9.8critical

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor

Sep 6, 2026🔧 No Patch
CVE-2026-19953
CVSS 6.5medium

URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep

Aug 31, 2026
CVE-2026-77781
CVSS 7.5high

Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys

Aug 21, 2026🔧 No Patch
CVE-2026-13048
CVSS 8.2high

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename

Aug 13, 2026🔧 No Patch

Monitor Perl in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.