CVE-2026-8463Disclosure(leont / crypt\)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch leont crypt\ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without checking that encoded_len is non-zero. When the encoded string is empty, the size_t subtraction underflows to SIZE_MAX and memchr scans adjacent heap memory looking for a '$' separator byte. A caller that invokes argon2_verify against a stored hash that may legitimately be empty (for example a placeholder row or a NULL column materialised as an empty string) reads out-of-bounds heap memory, which can crash the process or leak the position of an adjacent '$' byte into subsequent parsing.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-126CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crypt\

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-15); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
crypt\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-15: 2Mentions · 2026-06-05: 1Patch / Workaround · 2026-06-05: 1Technical Details · 2026-05-15: 2Technical Details · 2026-06-05: 105-1506-05
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-152
Disclosure2
2026-06-051
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-5089: YAML::Syck before 1.38 has an out-of-bounds read https://www.openwall.com/lists/oss-security/2026/05/12/16 CVE-2026-8463: Crypt::Argon2 from 0.017 before 0.031 perform a heap out-of-bounds read in argon2_verify on empty encoded input https://www.openwall.com/lists/oss-security/2026/05/13/4

    Post summary

    The post announces two new CVE vulnerabilities impacting CPAN modules, describing out‑of‑bounds read issues but offering no proof of concept, exploit, or patch information.

    10000167
    4.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-5089: YAML::Syck before 1.38 has an out-of-bounds read https://www.openwall.com/lists/oss-security/2026/05/12/16 CVE-2026-8463: Crypt::Argon2 from 0.017 before 0.031 perform a heap out-of-bounds read in argon2_verify on empty encoded input https://www.openwall.com/lists/oss-security/2026/05/13/4

    Post summary

    Two new Perl CPAN CVEs (CVE‑2026‑5089 and CVE‑2026‑8463) are disclosed, detailing out‑of‑bounds read vulnerabilities in YAML::Syck and Crypt::Argon2 with specified version ranges and links to advisories.

    1000049
    4.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora released security fixes for CVE-2026-8463, a denial-of-service flaw in perl-Crypt-Argon2 and related Perl build modules on Fedora 43 and 44, according to Fedora security advisories. https://threatcluster.io/cluster/fedora-43-and-44-address-critical-vulnerabilities-in-perl-mo-90d88dd4

    Post summary

    Fedora has applied patches for CVE-2026-8463, a denial‑of‑service vulnerability in perl-Crypt-Argon2 and related Perl build modules on Fedora 43 and 44.

    0000046
    311 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appleontcrypt\\--

Explore more