https://seclists.org/oss-sec/2026/q3/126: CVE-2026-13221: Perl versions through 5.43.9 produce silently incorct gular expssion matches when an alternation of mothan 65535 fixed string branches is compiled into a trie in Perl_study_chunk
Published Jul 13, 2026
·Updated
Affected Software
1 affected component
Perl Perl<=5.43.9
Frequently Asked Questions
1
What is the severity of CVE-2026-13221?
CVE-2026-13221 is considered a critical vulnerability affecting Perl versions through 5.43.9.
2
How do I fix CVE-2026-13221?
To fix CVE-2026-13221, upgrade Perl to a version later than 5.43.9 where the issue has been resolved.
3
What versions of Perl are affected by CVE-2026-13221?
CVE-2026-13221 affects all Perl versions through 5.43.9.
4
What is the nature of the vulnerability in CVE-2026-13221?
CVE-2026-13221 causes Perl to produce silently incorrect regular expression matches when specific conditions are met.
5
Are there any workarounds for CVE-2026-13221?
There are no effective workarounds for CVE-2026-13221; upgrading is the recommended solution.