#CPAN
All CosmicBytez Labs articles tagged #CPAN, across news, security advisories, how-to guides, and projects.
- Security
CVE-2016-15059 — Heap Buffer Overflow in Net::IDN::Punycode's XS Encoder
A decade-old heap overflow in Perl's Net::IDN::Punycode (encode_punycode, fixed in 2.301) was just scored CVSS 9.8 in NVD.
- Security
CVE-2011-10043: Perl Module::Load Arbitrary Module Injection Resurfaces
A decade-old CVSS 9.8 flaw in Perl's Module::Load (before 0.22) allows attackers to load arbitrary modules outside @INC via '::'-prefixed names. Now...
- Security
CVE-2026-9733: Mojolicious OAuth2 Weak PRNG Enables CSRF Session Hijacking
A critical flaw in the Mojolicious::Plugin::Web::Auth::OAuth2 Perl module uses a predictable SHA-1 state derived from epoch time and rand(), allowing...
- Security
CVE-2026-8507: Crypt::OpenSSL::PKCS12 Heap OOB Write — CVSS
A critical heap out-of-bounds write vulnerability in Crypt::OpenSSL::PKCS12 for Perl (versions through 1.94) can be triggered by parsing a malformed...
- Security
CVE-2025-15618: Perl Payment Module Uses Insecure
Business::OnlinePayment::StoredTransaction through version 0.01 for Perl generates its secret key using an MD5 hash of a single rand() call — a...