
Perl CPAN App::Ack before or through 3.10.0 CVE-2026-49145: Read arbitrary files via --files-from in a project .ackrc https://www.openwall.com/lists/oss-security/2026/07/08/7 CVE-2026-49146: Memory exhaustion https://www.openwall.com/lists/oss-security/2026/07/08/8 CVE-2026-49147: Print terminal escapes from filenames https://www.openwall.com/lists/oss-security/2026/07/08/9
Post summary
Three CVEs for Perl CPAN App::Ack are announced with brief technical details; no PoC, exploit, or patch information is provided.
