
Perl CPAN App::Ack before or through 3.10.0 CVE-2026-49145: Read arbitrary files via --files-from in a project .ackrc https://www.openwall.com/lists/oss-security/2026/07/08/7 CVE-2026-49146: Memory exhaustion https://www.openwall.com/lists/oss-security/2026/07/08/8 CVE-2026-49147: Print terminal escapes from filenames https://www.openwall.com/lists/oss-security/2026/07/08/9
Post summary
The text discloses new CVEs affecting Perl CPAN App::Ack, detailing arbitrary file read via --files-from and memory exhaustion, with references to OpenWall mailing‑list discussions.
