Perl
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 206 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 31, 1999 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
CVE-2026-19487: Perl versions from 5.9.4 befo5.41.9 produce incorct gular expssion match sults when a stale failuflag ends the Aho-Corasick pscan early in S_find_byclass
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
Monitor Perl in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.