
Perl CPAN CVE-2026-12205: Crypt::DSA before 1.21 reused the nonce across signatures, leading to private-key recovery https://www.openwall.com/lists/oss-security/2026/06/15/4 CVE-2026-12087: Socket before 2.041 have an out-of-bounds heap read https://www.openwall.com/lists/oss-security/2026/06/15/10
Post summary
The post announces two CVEs, summarizes their technical impact, but provides no evidence of exploitation, patches, or PoC code.

