CVE-2026-56018Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) the cleanup frees only the NodeSet structures and never the per-token contents buffers allocated in JsSetNodeContents; JsDiscardNode unlinks nodes without freeing their contents. Each token's contents buffer is therefore leaked on every call, and the two early returns taken when the node list is empty leak the whole NodeSet. A long-lived process that minifies repeatedly, such as an asset pipeline or a server-side minifier endpoint, grows in memory without bound until it exhausts available memory and is killed, causing denial of service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-30); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-30: 1Mentions · 2026-07-05: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-05: 106-3007-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-56017: JavaScript::Minifier::XS before 0.16 may crash with a NULL pointer dereference https://www.openwall.com/lists/oss-security/2026/06/29/16 CVE-2026-56018: JavaScript::Minifier::XS before 0.16 leak memory on every call to minify() https://www.openwall.com/lists/oss-security/2026/06/29/17

    Post summary

    The text announces two new CVEs (CVE-2026-56017 and CVE-2026-56018) for JavaScript::Minifier::XS, highlighting a crash due to a NULL pointer dereference and a memory leak, respectively.

    1000077
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56018 Memory Leak in JavaScript::Minifier::XS Before 0.16 for Perl https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56018

    Post summary

    New memory leak vulnerability (CVE-2026-56018) affecting JavaScript::Minifier::XS prior to version 0.16 for Perl has been announced.

    00000113
    4.1K followersView on X

Explore more