
Perl CPAN CVE-2026-13705: Imager before 1.032 has a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle https://www.openwall.com/lists/oss-security/2026/07/06/3 CVE-2026-13708: Imager::File::JPEG before 1.003 may leak heap memory https://www.openwall.com/lists/oss-security/2026/07/06/4
Post summary
The passage announces two new CVEs in Perl CPAN Imager, detailing the specific vulnerabilities and providing references to security mailing list posts, but offers no PoC, exploit, or active exploitation evidence.
