
Perl CPAN CVE-2026-56017: JavaScript::Minifier::XS before 0.16 may crash with a NULL pointer dereference https://www.openwall.com/lists/oss-security/2026/06/29/16 CVE-2026-56018: JavaScript::Minifier::XS before 0.16 leak memory on every call to minify() https://www.openwall.com/lists/oss-security/2026/06/29/17
Post summary
The post announces two new CVEs for JavaScript::Minifier::XS, describing a NULL pointer crash (CVE‑2026‑56017) and a memory leak on each minify() call (CVE‑2026‑56018); no PoC, exploit, or patch information is provided.
