
Perl CPAN CVE-2025-15618: Business::OnlinePayment::StoredTransaction versions through 0.01 uses an insecure secret key https://www.openwall.com/lists/oss-security/2026/03/31/7 CVE-2024-14031: Sereal::Encoder versions from 4.000 through 4.009_002 buffer overwrite in the Zstandard library https://www.openwall.com/lists/oss-security/2026/03/31/8
Post summary
Two Perl CPAN modules are disclosed as vulnerable—an insecure secret key in Business::OnlinePayment::StoredTransaction and a buffer overwrite in Sereal::Encoder—but no PoC, exploit, or patch information is provided.

