Executive brief
String::Util is a Perl library used for common string manipulation tasks. A vulnerability in its whitespace trimming functions allows an attacker to cause a denial-of-service condition by providing specially crafted input. This can lead to high CPU usage and application hangs, potentially disrupting services that process user-supplied text.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in String::Util versions prior to 1.36. The trim and rtrim functions utilized a regular expression (s/\s*$//u) that caused quadratic backtracking when processing long runs of whitespace followed by non-whitespace characters. This occurs because the greedy \s* matcher retries at every offset when the $ anchor fails. An attacker can exploit this by submitting strings with large amounts of trailing whitespace to any application interface that passes untrusted input to these functions. The issue was resolved in version 1.36 by updating the regex to use \s+$.
Affected products
- BAKERSCOT String::Util < 1.36
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory
- 2026-07-06: patched: Patch committed to GitHub repository