CVE-2026-8376Disclosure(perl / perl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-680

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • perl

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
perl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-26: 2Mentions · 2026-05-30: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-30: 105-2605-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-262
Disclosure1General1
2026-05-301
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-8376: Perl: Heap buffer overflow https://www.openwall.com/lists/oss-security/2026/05/26/1 when compiling regular expressions with a repeated fixed string on 32-bit builds, affects versions through 5.43.10

    Post summary

    The text announces a heap buffer overflow in Perl that occurs when compiling regexes with repeated fixed strings on 32‑bit builds, affecting versions up to 5.43.10. No PoC, exploit code, or patch information is provided.

    00042590
    4.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Perl Heap Buffer Overflow in Regex Compiler (CVE-2026-8376) A heap buffer overflow in Perl is triggered when compiling regular expressions containing a repeated fixed string on 32-bit builds. The function checks the joined substring buffer size in characters rather than bytes, so mincount * l can overflow SSize_t, resulting in an undersized SvGROW allocation and a subsequent out-of-bounds write. Any application that compiles attacker-controlled regular expressions on a 32-bit Perl build is exploitable at compile time (CVSS 9.8). 👉 Affected: Perl ≤ 5.43.10

    Post summary

    The text announces a critical heap buffer overflow vulnerability (CVE-2026-8376) in Perl's regex compiler, providing technical details but omitting PoC, exploitation evidence, or mitigation information.

    0001080
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8376 perl https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8376

    Post summary

    The post merely states the CVE identifier and links to a Vulmon page, offering no substantive details on exploitation, mitigations, or technical characteristics.

    0000061
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appperlperl---

Explore more