CVE-2026-12087Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-16); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-16: 1Mentions · 2026-06-18: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 106-1606-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-12205: Crypt::DSA before 1.21 reused the nonce across signatures, leading to private-key recovery https://www.openwall.com/lists/oss-security/2026/06/15/4 CVE-2026-12087: Socket before 2.041 have an out-of-bounds heap read https://www.openwall.com/lists/oss-security/2026/06/15/10

    Post summary

    The post announces two CVEs, summarizes their technical impact, but provides no evidence of exploitation, patches, or PoC code.

    10010157
    4.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Out-of-Bounds Heap Read in Perl's Socket Module (CVE-2026-12087) A vulnerability in Perl's Socket module (pack_ip_mreq_source function) allows an out-of-bounds heap read due to improper length validation. Attackers supplying a short source value can trigger memory reads beyond the buffer, potentially exposing sensitive adjacent heap data. This flaw could lead to information disclosure, aiding further exploitation or privilege escalation. 👉 Affected: Socket <2.041 | Upgrade to 2.041

    Post summary

    The tweet discloses CVE-2026-12087, an out-of-bounds heap read in Perl's Socket module, and advises upgrading to version 2.041 to mitigate the risk.

    0000069
    217 followersView on X

Explore more