{"schema_version":1,"title":"Perl CPAN vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in Perl CPAN: 2 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85491, was published on 24 September 2026. 3 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/perl-cpan","json_url":"https://junglewise.ai/threats/vendors/perl-cpan.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/perl-cpan","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":12,"critical":0,"exploited":0,"last_7_days":2,"last_30_days":2,"last_90_days":3,"last_365_days":12},"latest":[{"cve":"CVE-2026-85491","cvss":8.8,"epss":0.0035,"slug":"cve-2026-85491-catalyst-seal-versions-before-0-03-for-perl-allow-one-request-to","title":"Catalyst::Seal authorization bypass via dispatch memoization","severity":"high","exploited":false,"published_at":"2026-09-24T22:17:02.027+00:00","url":"https://junglewise.ai/threats/cve-2026-85491-catalyst-seal-versions-before-0-03-for-perl-allow-one-request-to"},{"cve":"CVE-2026-87082","cvss":7.5,"epss":0.0068,"slug":"cve-2026-87082-net-idn-punycode-versions-before-2-590-for-perl-hang-crash-or","title":"Perl Net::IDN::Punycode infinite loop and crash in encode_punycode","severity":"high","exploited":false,"published_at":"2026-09-22T08:16:40.973+00:00","url":"https://junglewise.ai/threats/cve-2026-87082-net-idn-punycode-versions-before-2-590-for-perl-hang-crash-or"},{"cve":"CVE-2026-16766","cvss":8.8,"slug":"cve-2026-16766-perl-catalyst-view-wkhtmltopdf-shell-command-injection-in-render","title":"Perl Catalyst-View-Wkhtmltopdf shell command injection in render options","severity":"info","exploited":false,"published_at":"2026-07-25T09:16:32+00:00","url":"https://junglewise.ai/threats/cve-2026-16766-perl-catalyst-view-wkhtmltopdf-shell-command-injection-in-render"},{"cve":"CVE-2026-12205","cvss":0,"slug":"cve-2026-12205-perl-crypt-dsa-private-key-recovery-via-nonce-reuse","title":"Perl Crypt::DSA private key recovery via nonce reuse","severity":"info","exploited":false,"published_at":"2026-06-15T23:16:43.15+00:00","url":"https://junglewise.ai/threats/cve-2026-12205-perl-crypt-dsa-private-key-recovery-via-nonce-reuse"},{"cve":"CVE-2026-48962","cvss":0,"slug":"cve-2026-48962-perl-io-compress-eval-injection-in-file-globmapper","title":"Perl IO::Compress eval injection in File::GlobMapper","severity":"info","exploited":false,"published_at":"2026-05-27T04:16:31.333+00:00","url":"https://junglewise.ai/threats/cve-2026-48962-perl-io-compress-eval-injection-in-file-globmapper"},{"cve":"CVE-2026-48961","cvss":0,"slug":"cve-2026-48961-perl-io-compress-crash-in-zipdetails-cli-tool","title":"Perl IO::Compress crash in zipdetails CLI tool","severity":"info","exploited":false,"published_at":"2026-05-27T04:16:31.21+00:00","url":"https://junglewise.ai/threats/cve-2026-48961-perl-io-compress-crash-in-zipdetails-cli-tool"},{"cve":"CVE-2025-15649","cvss":0,"slug":"cve-2025-15649-perl-io-uncompress-unzip-uncaught-exception-in-dos-date-parsing","title":"Perl IO::Uncompress::Unzip uncaught exception in DOS date parsing","severity":"info","exploited":false,"published_at":"2026-05-27T04:16:23.873+00:00","url":"https://junglewise.ai/threats/cve-2025-15649-perl-io-uncompress-unzip-uncaught-exception-in-dos-date-parsing"},{"cve":"CVE-2026-8647","cvss":3.3,"slug":"cve-2026-8647-perl-crypt-scryptkdf-weak-prng-use-in-random-bytes","title":"Perl Crypt::ScryptKDF weak PRNG use in random_bytes","severity":"info","exploited":false,"published_at":"2026-05-26T23:16:21.247+00:00","url":"https://junglewise.ai/threats/cve-2026-8647-perl-crypt-scryptkdf-weak-prng-use-in-random-bytes"},{"cve":"CVE-2026-8507","cvss":9.8,"slug":"cve-2026-8507-perl-crypt-openssl-pkcs12-heap-overflow-in-print-attribute","title":"Perl Crypt::OpenSSL::PKCS12 heap overflow in print_attribute","severity":"info","exploited":false,"published_at":"2026-05-17T19:16:24.59+00:00","url":"https://junglewise.ai/threats/cve-2026-8507-perl-crypt-openssl-pkcs12-heap-overflow-in-print-attribute"},{"cve":"CVE-2026-8704","slug":"cve-2026-8704-perl-crypt-dsa-insecure-file-handling-via-2-argument-open","title":"Perl Crypt::DSA insecure file handling via 2-argument open","severity":"info","exploited":false,"published_at":"2026-05-15T23:16:21.74+00:00","url":"https://junglewise.ai/threats/cve-2026-8704-perl-crypt-dsa-insecure-file-handling-via-2-argument-open"},{"cve":"CVE-2026-8700","cvss":0,"slug":"cve-2026-8700-perl-crypt-dsa-insufficient-entropy-in-seed-generation","title":"Perl Crypt::DSA insufficient entropy in seed generation","severity":"info","exploited":false,"published_at":"2026-05-15T22:16:57.02+00:00","url":"https://junglewise.ai/threats/cve-2026-8700-perl-crypt-dsa-insufficient-entropy-in-seed-generation"},{"cve":"CVE-2026-6659","cvss":7.5,"epss":0.0002,"slug":"cve-2026-6659-crypt-passwdmd5-weak-prng-in-salt-generation","title":"Crypt::PasswdMD5 weak PRNG in salt generation","severity":"high","exploited":false,"published_at":"2026-05-08T18:16:34.183+00:00","url":"https://junglewise.ai/threats/cve-2026-6659-crypt-passwdmd5-weak-prng-in-salt-generation"}],"vendor":{"hub":true,"name":"Perl CPAN","slug":"perl-cpan","homepage":"https://www.cpan.org/","description":"The Comprehensive Perl Archive Network is a repository of software written in the Perl programming language.","url":"https://junglewise.ai/threats/vendors/perl-cpan"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"most_severe":[{"cve":"CVE-2026-85491","cvss":8.8,"epss":0.0035,"slug":"cve-2026-85491-catalyst-seal-versions-before-0-03-for-perl-allow-one-request-to","title":"Catalyst::Seal authorization bypass via dispatch memoization","severity":"high","exploited":false,"published_at":"2026-09-24T22:17:02.027+00:00","url":"https://junglewise.ai/threats/cve-2026-85491-catalyst-seal-versions-before-0-03-for-perl-allow-one-request-to"},{"cve":"CVE-2026-87082","cvss":7.5,"epss":0.0068,"slug":"cve-2026-87082-net-idn-punycode-versions-before-2-590-for-perl-hang-crash-or","title":"Perl Net::IDN::Punycode infinite loop and crash in encode_punycode","severity":"high","exploited":false,"published_at":"2026-09-22T08:16:40.973+00:00","url":"https://junglewise.ai/threats/cve-2026-87082-net-idn-punycode-versions-before-2-590-for-perl-hang-crash-or"},{"cve":"CVE-2026-6659","cvss":7.5,"epss":0.0002,"slug":"cve-2026-6659-crypt-passwdmd5-weak-prng-in-salt-generation","title":"Crypt::PasswdMD5 weak PRNG in salt generation","severity":"high","exploited":false,"published_at":"2026-05-08T18:16:34.183+00:00","url":"https://junglewise.ai/threats/cve-2026-6659-crypt-passwdmd5-weak-prng-in-salt-generation"},{"cve":"CVE-2026-8507","cvss":9.8,"slug":"cve-2026-8507-perl-crypt-openssl-pkcs12-heap-overflow-in-print-attribute","title":"Perl Crypt::OpenSSL::PKCS12 heap overflow in print_attribute","severity":"info","exploited":false,"published_at":"2026-05-17T19:16:24.59+00:00","url":"https://junglewise.ai/threats/cve-2026-8507-perl-crypt-openssl-pkcs12-heap-overflow-in-print-attribute"},{"cve":"CVE-2026-16766","cvss":8.8,"slug":"cve-2026-16766-perl-catalyst-view-wkhtmltopdf-shell-command-injection-in-render","title":"Perl Catalyst-View-Wkhtmltopdf shell command injection in render options","severity":"info","exploited":false,"published_at":"2026-07-25T09:16:32+00:00","url":"https://junglewise.ai/threats/cve-2026-16766-perl-catalyst-view-wkhtmltopdf-shell-command-injection-in-render"},{"cve":"CVE-2026-8647","cvss":3.3,"slug":"cve-2026-8647-perl-crypt-scryptkdf-weak-prng-use-in-random-bytes","title":"Perl Crypt::ScryptKDF weak PRNG use in random_bytes","severity":"info","exploited":false,"published_at":"2026-05-26T23:16:21.247+00:00","url":"https://junglewise.ai/threats/cve-2026-8647-perl-crypt-scryptkdf-weak-prng-use-in-random-bytes"},{"cve":"CVE-2026-12205","cvss":0,"slug":"cve-2026-12205-perl-crypt-dsa-private-key-recovery-via-nonce-reuse","title":"Perl Crypt::DSA private key recovery via nonce reuse","severity":"info","exploited":false,"published_at":"2026-06-15T23:16:43.15+00:00","url":"https://junglewise.ai/threats/cve-2026-12205-perl-crypt-dsa-private-key-recovery-via-nonce-reuse"},{"cve":"CVE-2026-48962","cvss":0,"slug":"cve-2026-48962-perl-io-compress-eval-injection-in-file-globmapper","title":"Perl IO::Compress eval injection in File::GlobMapper","severity":"info","exploited":false,"published_at":"2026-05-27T04:16:31.333+00:00","url":"https://junglewise.ai/threats/cve-2026-48962-perl-io-compress-eval-injection-in-file-globmapper"},{"cve":"CVE-2026-48961","cvss":0,"slug":"cve-2026-48961-perl-io-compress-crash-in-zipdetails-cli-tool","title":"Perl IO::Compress crash in zipdetails CLI tool","severity":"info","exploited":false,"published_at":"2026-05-27T04:16:31.21+00:00","url":"https://junglewise.ai/threats/cve-2026-48961-perl-io-compress-crash-in-zipdetails-cli-tool"},{"cve":"CVE-2025-15649","cvss":0,"slug":"cve-2025-15649-perl-io-uncompress-unzip-uncaught-exception-in-dos-date-parsing","title":"Perl IO::Uncompress::Unzip uncaught exception in DOS date parsing","severity":"info","exploited":false,"published_at":"2026-05-27T04:16:23.873+00:00","url":"https://junglewise.ai/threats/cve-2025-15649-perl-io-uncompress-unzip-uncaught-exception-in-dos-date-parsing"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Perl CPAN Crypt-Dsa-Perl","slug":"crypt-dsa","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/crypt-dsa"},{"name":"Perl CPAN Crypt::OpenSSL::PKCS12","slug":"crypt-openssl-pkcs12","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/crypt-openssl-pkcs12"},{"name":"Perl CPAN IO::Compress","slug":"io-compress","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/io-compress"}]}