THREAT OPS › Threat News › [NVD] CVE-2026-8376 (CRITICAL 9.8) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined substring b
[NVD] CVE-2026-8376 (CRITICAL 9.8) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring b
CVE-2026-8376 CVSS: 9.8 CRITICAL Published: 2026-05-26T00:16:57.150
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quanti
Indicators of compromise
- CVE-2026-8376cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-8376