๐Ÿ” CVE Alert

CVE-2026-107373

UNKNOWN 0.0

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses $var = std::string( SvPV_nolen($arg), SvCUR($arg) ) However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first. When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.

CWE CWE-125
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new unknown vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes github.com: https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d rt.cpan.org: https://rt.cpan.org/Public/Bug/Display.html?id=94110 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-80490