PT-2026-103330 · Cpan · Algorithm::Ahocorasick::Xs

CVE-2026-80490

·

Published

2026-09-30

·

Updated

2026-09-30

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Algorithm::AhoCorasick::XS versions prior to 0.05
Description An out-of-bounds read occurs when the software reads the haystack string length before the scalar is stringified. The matches(), first match(), and match details() methods utilize the T STD STRING typemap to translate Perl scalars into strings. This process uses the SvPV macro for stringification and the SvCUR macro to determine length. If the input scalars are references, integers, or floats, the SvCUR macro may return an invalid length if executed before stringification, potentially causing the process to abort. This issue is triggered when the haystack is a numeric value, such as data from decoded JSON, numeric database columns, or blessed objects.
Recommendations Update Algorithm::AhoCorasick::XS to version 0.05 or later.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80490

Affected Products

Algorithm::Ahocorasick::Xs