CVE-2011-10043Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to specify arbitrary module paths. Attackers able to influence module names passed to load could use that bug to execute arbitrary code.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-145

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-07: 107-07
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Perl Module::Load Arbitrary Module Load / Code Execution (CVE-2011-10043) Perl's Module::Load before 0.22 didn't properly restrict module names in load(). A name starting with "::" could specify an arbitrary module path outside @INC, so an attacker who can influence the module name passed to load() could get an arbitrary module loaded and its code executed. This is an old (2011) bug only now assigned a CVE, fixed back in Module::Load 0.22. Real-world impact is conditional on an app passing attacker-controlled input into load() - uncommon - so the listed CVSS 9.8 (CISA-ADP) is an upper bound rather than a typical case. 👉Upgrade Module::Load to 0.22 or later.

    Post summary

    CVE-2011-10043 allows arbitrary module loading via Module::Load; the issue is mitigated by upgrading to 0.22 or later, and no active exploitation is reported.

    0000073
    243 followersView on X

Explore more