THREAT OPS › Threat News › [NVD] CVE-2026-13221 (CRITICAL 9.1) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.
When such branches are combi
[NVD] CVE-2026-13221 (CRITICAL 9.1) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combi
CVE-2026-13221 CVSS: 9.1 CRITICAL Published: 2026-07-13T17:16:48.923
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.
When such branches are combined into a trie, the delta between the first branc
Indicators of compromise
- CVE-2026-13221cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-13221