Critical CPU Exhaustion Vulnerabilities in Perl Modules Announced

Critical CPU Exhaustion Vulnerabilities in Perl Modules Announced

First seen 1 Sep 2026, 13:00 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

Mageia has issued advisories for two critical vulnerabilities affecting Perl modules Date::Manip and HTTP::Date. The vulnerabilities allow for CPU exhaustion through specific parsing methods, impacting versions of both modules. Date::Manip versions up to 6.99 are affected by non-ASCII decimal digits causing corrupted dates and quadratic backtracking issues. HTTP::Date versions before 6.08 are vulnerable to polynomial regex backtracking in date parsing. These vulnerabilities could potentially lead to denial of service conditions. The CVEs associated with these vulnerabilities are CVE-2026-60074 and CVE-2026-14741. Users are urged to update to the latest versions to mitigate these risks. The advisories were published on September 1, 2026, and highlight the urgency of addressing these flaws.

Key Points: • CVE-2026-60074 and CVE-2026-14741 expose critical CPU exhaustion vulnerabilities. • Affected Perl modules include Date::Manip (up to 6.99) and HTTP::Date (before 6.08). • Immediate updates are recommended to prevent potential denial of service attacks.

Timeline

2026-07-30
CVE-2026-60074 published
CVE-2026-60074 details a vulnerability in Date::Manip affecting versions up to 6.99, allowing CPU exhaustion.
Linuxsecurity
2026-09-01
Mageia advisories published
Mageia released advisories for vulnerabilities in Date::Manip and HTTP::Date, urging immediate updates.
Linuxsecurity
2026-09-01
CVE-2026-14741 published
CVE-2026-14741 describes a vulnerability in HTTP::Date allowing CPU exhaustion via regex backtracking.
Linuxsecurity