CVE-2026-8721General

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on the buffer. Any password byte at or after the first NULL is silently dropped. Binary / KDF-derived / HMAC-derived passwords lose entropy without any warnings.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-170

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-17); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Mentions · 2026-05-20: 1Mentions · 2026-06-01: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-20: 105-1705-1805-2006-01
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-171
General1
2026-05-181
Disclosure1
2026-05-201
Disclosure1
2026-06-011
General1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-8507: Crypt::OpenSSL::PKCS12 through 1.94 have out of bound (OOB) write flaws https://www.openwall.com/lists/oss-security/2026/05/17/5 CVE-2026-8721: Crypt::OpenSSL::PKCS12 through 1.94 truncates passwords with embedded NULLs https://www.openwall.com/lists/oss-security/2026/05/17/6

    Post summary

    The text announces two new CVEs in Crypt::OpenSSL::PKCS12 through 1.94, detailing an out-of-bounds write and password truncation issue, without any evidence of exploitation, PoC, or patch information.

    10010175
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8721 Password Truncation Vulnerability in Crypt::OpenSSL::PKCS12 Through Versi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8721 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post merely announces a password truncation vulnerability (CVE‑2026‑8721) via Vulmon links, without any PoC, exploitation details, or mitigation information.

    0101098
    4.0K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-8721 Perlの脆弱性について https://www.cybernote.click/2026/05/30/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-8721-%e5%af%be%e8%b1%a1%e3%82%b7%e3%82%b9%e3%83%86%e3%83%a0%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84/ #IT #Security #cybersecurity

    Post summary

    The post merely announces the existence of CVE‑2026‑8721 with a link to an article, offering no technical details or exploit information.

    0000039
    211 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8721 Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes throu… https://www.cve.org/CVERecord?id=CVE-2026-8721

    Post summary

    The text announces a password-truncation flaw in Crypt::OpenSSL::PKCS12 modules that drops embedded NULLs, but does not provide proof of exploitation, a PoC, a patch, or evidence of active attacks.

    00000173
    57.5K followersView on X

Explore more