Junglewise Threat Intelligence

CVE-2026-82560: Perl Pod::Text denial of service via pathological =over nesting

CVE-2026-82560 · Severity: high · CVSS 7.5 · Published 2026-09-19

Vendors: Perl.

Executive brief

Pod::Text is a Perl module that converts POD (Plain Old Documentation) format into plain text. An attacker can craft a malicious POD document with deeply nested =over directives that causes the formatter to hang indefinitely and consume all available memory, preventing legitimate use of systems that process untrusted documentation.

Technical details

The vulnerability exists in the wrap() method where deeply nested =over directives cause the margin to equal or exceed the output width, creating a pathological condition where the line-splitting regex matches an empty string on every pass. This causes an infinite loop that appends margin padding to the output, exhausting memory and CPU resources. The fix adds a validation check to detect when margin width exceeds output width and forces the margin to zero, preventing the infinite loop.

Affected products

  • Perl Pod::Text before 6.1.1

Timeline

  • 2026-09-19: disclosed
  • 2026-08-29: patched

References