SecAlerts
cpan logo

cpan

Security Risk Profile

52
/100
medium

Security Risk Score

Comprehensive risk assessment based on 26 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 31, 2004 to present

26
Total CVEs
14
Critical+High
0
Exploited
10
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
52/100
medium
🆕 3Fresh (<7d)📈 10 in Last 30 Days

Severity Distribution

Critical
5
High
9
Medium
6
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Weak RNG
2
2
Command Injection
2
3
XSS
2
4
SSRF
1
5
CSRF
1

Most Affected Products

1. CPAN Ui\31
2. CPAN CPAN.pm2
3. CPAN Safe.pm2
4. CPAN Net::SAML2 (Perl)1
5. CPAN Perl XML::Sig1

Recent Vulnerabilities

See more →
CVE-2026-18092
CVSS 8.1high

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree

8/3/2026🔧 No Patch
CVE-2026-9487
CVSS 9.1EPSS 0%critical

XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID

8/3/2026🔧 No Patch
CVE-2026-18536
CVSS 7.5high

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP

8/1/2026🔧 No Patch
CVE-2026-17552
CVSS 9.1critical

Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call

7/27/2026🔧 No Patch
CVE-2026-59142
CVSS 9.1critical

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy

7/21/2026🔧 No Patch
CVE-2026-64194
CVSS 7.5high

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains

7/20/2026🔧 No Patch
CVE-2026-13082
CVSS 5.3medium

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets

7/17/2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/159
unknown

CVE-2026-57075: YAML::Syck versions befo1.47 for Perl allow an out-of-bounds ad via a signed-char lookup-table index in syck_base64dec

7/16/2026🔧 No Patch
RHSA-2026:39878
unknown

Important: perl-XML-LibXML security update

7/15/2026🔧 No Patch
CVE-2026-13708
CVSS 7.5high

Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol

7/6/2026🔧 No Patch

Monitor cpan in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.