Executive brief
Pod::Text is a Perl module that converts POD (Plain Old Documentation) format into plain text. An attacker can craft a malicious POD document with deeply nested =over directives that causes the formatter to hang indefinitely and consume all available memory, preventing legitimate use of systems that process untrusted documentation.
Technical details
The vulnerability exists in the wrap() method where deeply nested =over directives cause the margin to equal or exceed the output width, creating a pathological condition where the line-splitting regex matches an empty string on every pass. This causes an infinite loop that appends margin padding to the output, exhausting memory and CPU resources. The fix adds a validation check to detect when margin width exceeds output width and forces the margin to zero, preventing the infinite loop.
Affected products
- Perl Pod::Text before 6.1.1
Timeline
- 2026-09-19: disclosed
- 2026-08-29: patched