CVE-2025-15649: IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date
Published May 27, 2026
·Updated
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date
Affected Software
5 affected componentsFixes available
cpan/IO::Uncompress::Unzip<2.215
Microsoft azl3 perl 5.38.2-509
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IO::Uncompress::Unzipto a version that resolves this vulnerability.Fixed in 2.215 - Upgrade
Upgrade
IO::Uncompress::Unzipto a version that resolves this vulnerability.Patch CVE-2025-15649
Event History
May 27, 2026
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
May 31, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:04 AM
DescriptionSeverity
Aug 15, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15649?
CVE-2025-15649 is rated with a risk score of 30.
2
How do I fix CVE-2025-15649?
To remediate CVE-2025-15649, upgrade to IO-Compress version 2.215 or later.
3
What software is affected by CVE-2025-15649?
CVE-2025-15649 affects the IO::Uncompress::Unzip module for Perl.
4
What issue does CVE-2025-15649 cause?
CVE-2025-15649 causes uncaught exceptions when parsing zip headers with malformed DOS dates.
5
When was CVE-2025-15649 published?
CVE-2025-15649 was published on May 27, 2026.