-Infinity
0

CPAN Net::SAML2 (Perl)Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree

Risk 59
Severity
8.1
First published (updated )

CPAN Perl XML::SigXML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID

Risk 66
Severity
9.1
First published (updated )

CPAN Data::EntropyData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP

Risk 43
Severity
7.5
First published (updated )

CPAN Plack::App::PrerenderPlack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call

Risk 70
Severity
9.1
First published (updated )

CPAN Data::HashMap::SharedData::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CPAN Net::DNSNet::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains

Risk 46
Severity
7.5
First published (updated )

CPAN GD::SecurityImageGD::SecurityImage versions through 1.75 for Perl use rand to generate secrets

Risk 28
Severity
5.3
First published (updated )

oss-secCVE-2026-57075: YAML::Syck versions befo1.47 for Perl allow an out-of-bounds ad via a signed-char lookup-table index in syck_base64dec

CPAN perl-XML-LibXMLImportant: perl-XML-LibXML security update

Risk 26
First published (updated )

CPAN ImagerImager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CPAN Plack::Middleware::OAuthPlack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter

Risk 62
Severity
8.1
First published (updated )

CPAN GDGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle

Risk 91
Severity
9.8
First published (updated )

CVE-2025-40928: JSON::XS befoversion 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified

CPAN CGI::SimpleCGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw

Risk 51
Severity
7.3
First published (updated )

CVE-2011-10007: File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `gp()` encounters a crafted file name

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CPAN Crypt::CBCCrypt::CBC versions between 1.21 and 3.05 for Perl may use insecure rand() function for cryptographic functions

Risk 21
Severity
4
First published (updated )

CVE-2023-7101: Spreadsheet::ParseExcel for Perl is vulnerable to arbitrary code execution

CPAN CPAN.pmCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

Risk 19
Severity
4
First published (updated )

Perl's HTTP::Tiny has insecure TLS cert default, affecting CPAN.pm and other modules

CPAN Parallel\Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CPAN File\_is_safe in the File::Temp module for Perl does not properly handle symlinks.

Risk 43
Severity
7.5
First published (updated )

CPAN Batch\The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

Risk 43
Severity
7.5
First published (updated )

CPAN Safe.pmSafe.pm 2.26 and earlier (except 2.20 through 2.23 if using a threads-enabled Perl), when used in P…

Risk 19
Severity
4
First published (updated )

CPAN Safe.pmSafe.pm 2.24 and earlier, when used in Perl 5.10.0 and earlier, may allow attackers to break out of …

Risk 19
Severity
4
First published (updated )

CPAN Ui\Command Injection

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CPAN Www FormXSS

Risk 22
Severity
4.3
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203