Multiple Vulnerabilities Discovered in Perl Affecting Security and Stability

Multiple Vulnerabilities Discovered in Perl Affecting Security and Stability

First seen 27 Aug 2026, 14:16 UTC Ubuntu 72.5

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in Perl have been identified, allowing potential attackers to exploit various flaws. Key issues include improper handling of source addresses in the Socket module (CVE-2026-12087), incorrect processing of regular expressions (CVE-2026-13221), and issues with pack/unpack functions (CVE-2026-57432). These vulnerabilities could lead to information disclosure, denial of service, or even arbitrary code execution. Affected systems include any utilizing Perl, particularly those processing user inputs or handling files. The vulnerabilities were disclosed between May and July 2026, with proof-of-concept code for CVE-2026-12087 released shortly before the latest advisory. Administrators are advised to apply patches promptly to mitigate risks. The situation is evolving, with ongoing assessments of the vulnerabilities' impact.

Key Points: • Multiple vulnerabilities in Perl could lead to information disclosure and denial of service. • CVE-2026-12087 is particularly critical due to its potential for memory reading. • Administrators should apply patches immediately to secure affected systems.

Timeline

2026-05-26
CVE-2026-9538 published
A vulnerability affecting Perl was disclosed, allowing potential denial of service.
Ubuntu
2026-05-27
CVE-2025-15649 and CVE-2026-48959 published
Two vulnerabilities were disclosed, impacting Perl's handling of certain inputs.
Ubuntu
2026-05-27
CVE-2026-48962 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-15
CVE-2026-12087 published
A critical vulnerability was disclosed, allowing attackers to read sensitive information from memory.
Ubuntu
2026-07-07
CVE-2026-7017 published
A vulnerability in Perl's HTTP::Tiny module was disclosed, potentially exposing sensitive information.
Ubuntu
2026-07-13
CVE-2026-13221 and CVE-2026-57432 published
Two vulnerabilities were disclosed, affecting Perl's regular expressions and pack/unpack functions.
Ubuntu
2026-07-13
CVE-2026-57433 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-24
PoC for CVE-2026-12087 released
Proof-of-concept code for a critical Perl vulnerability was made public, increasing exploitation risk.
Ubuntu
2026-08-27
USN-8684-1 advisory published
New vulnerabilities in Perl were disclosed, urging immediate patching by administrators.
Ubuntu