{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/perl-5.45.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-15534"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Perl (5.45.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Perl"],"content_html":"\u003cp\u003ePerl versions through 5.45.1 contain a critical memory corruption vulnerability in the regular expression engine. The issue originates within the S_regmatch function due to an undersized superlinear cache. When processing specific, maliciously crafted regular expressions, the engine may perform out-of-bounds heap reads and writes. This flaw represents a significant risk for any application utilizing Perl to process user-supplied input via regex patterns, as it could be leveraged to crash services or achieve arbitrary code execution in the context of the Perl interpreter. Organizations utilizing Perl in web applications, CGI scripts, or data processing pipelines should prioritize updating their environment to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability can lead to memory corruption, resulting in either a denial-of-service (process crash) or potential remote code execution. The impact is broad given Perl's prevalence in backend infrastructure, legacy web applications, and various system administration utilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Perl distributions to a version later than 5.45.1 as soon as patches are released by the Perl community.\u003c/li\u003e\n\u003cli\u003eReview applications that utilize Perl for processing untrusted or external input via regular expressions to identify potential exposure points.\u003c/li\u003e\n\u003cli\u003eAudit system logs for unexpected crashes of Perl-based services which may indicate failed exploitation attempts or memory instability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T09:57:28Z","date_published":"2026-08-11T09:57:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-perl-heap-vuln/","summary":"Perl versions through 5.45.1 contain a vulnerability in the S_regmatch function leading to out-of-bounds heap reads and writes during regex processing, which may allow for arbitrary code execution.","title":"Out-of-Bounds Memory Corruption in Perl Regular Expression Engine","url":"https://feed.craftedsignal.io/briefs/2026-08-perl-heap-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Perl (5.45.1)","version":"https://jsonfeed.org/version/1.1"}