
Perl CPAN CVE-2026-13705: Imager before 1.032 has a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle https://www.openwall.com/lists/oss-security/2026/07/06/3 CVE-2026-13708: Imager::File::JPEG before 1.003 may leak heap memory https://www.openwall.com/lists/oss-security/2026/07/06/4
Post summary
Two new CVEs (CVE‑2026‑13705 and CVE‑2026‑13708) for the Perl CPAN Imager library are disclosed, detailing heap memory vulnerabilities without mention of exploits, patches, or false positives.
