
Perl CPAN CVE-2026-7111: Text::CSV_XS: Use-after-free, may enable type confusion or memory corruption https://www.openwall.com/lists/oss-security/2026/04/29/17 CVE-2026-7381: Plack::Middleware::XSendfile: Client-controlled path rewriting https://www.openwall.com/lists/oss-security/2026/04/29/27
Post summary
The text announces two new Perl CPAN module vulnerabilities: CVE-2026-7111 is a use-after-free that could lead to memory corruption, whereas CVE-2026-7381 permits client-controlled path rewriting.


