Executive brief
Text::LineFold is a Perl module used to format and wrap text for plain-text emails and documents. A flaw in how it handles certain special characters (like vertical tabs or form feeds) causes it to duplicate the entire input string multiple times. This can lead to excessive memory and CPU usage, potentially allowing an attacker to crash an application or cause a denial of service by providing specially crafted text.
Technical details
The Text::LineFold module (part of the Unicode-LineBreak distribution) contains a logic error in its line-folding implementation. When processing input strings containing specific line break characters (such as VT or FF), the module splits the string into segments but incorrectly applies the break function to the entire original string for every segment identified. This results in an amplification effect where the output size grows relative to the number of special characters present. An attacker can exploit this to cause asymmetric resource consumption (CWE-405) and inefficient algorithmic complexity (CWE-407), leading to a denial of service. A patch has been proposed in the Unicode-LineBreak GitHub repository.
Affected products
- Perl CPAN (Unicode-LineBreak distribution) Text::LineFold through 2019.001
Timeline
- 2026-05-30: disclosed
- 2026-05-30: advisory: NVD publication date
- 2026-05-30: other: Pull request for fix submitted on GitHub