CVE-2026-8507Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew().

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-20)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Mentions · 2026-05-20: 2Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-20: 105-1705-1805-20
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-171
Disclosure1
2026-05-181
Disclosure1
2026-05-202
Disclosure1General1
Full discourse4 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2020-17103 2 - CVE-2026-8507 3 - CVE-2026-3854 4 - CVE-2026-46333 5 - CVE-2025-54957 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVEs as trending, includes hashtags and a dashboard link, but provides no exploitation, patch, technical, or debunking details.

    001101.2K
    1.7K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-8507: Crypt::OpenSSL::PKCS12 through 1.94 have out of bound (OOB) write flaws https://www.openwall.com/lists/oss-security/2026/05/17/5 CVE-2026-8721: Crypt::OpenSSL::PKCS12 through 1.94 truncates passwords with embedded NULLs https://www.openwall.com/lists/oss-security/2026/05/17/6

    Post summary

    Two new CVEs affecting Crypt::OpenSSL::PKCS12 (versions up to 1.94) are disclosed: CVE‑2026‑8507 involves an out‑of‑bounds write, while CVE‑2026‑8721 causes password truncation when NULL bytes are present.

    10010175
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8507 Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out of bound (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) att… https://www.cve.org/CVERecord?id=CVE-2026-8507

    Post summary

    The post announces CVE‑2026‑8507, a Perl Crypt::OpenSSL::PKCS12 out‑of‑bounds write vulnerability triggered by large OCTET/BIT STRING inputs, offering basic technical details but no PoC, exploit, or patch information.

    00000209
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8507 Out-of-Bounds Write Vulnerability in Crypt::OpenSSL::PKCS12 Through Version 1.94 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8507

    Post summary

    CVE-2026-8507 is an out‑of‑bounds write vulnerability affecting Crypt::OpenSSL::PKCS12 up to version 1.94; the text provides technical detail but no PoC, exploit code, patch, or evidence of active exploitation.

    0000060
    4.0K followersView on X

Explore more