USN-8684-1: Perl vulnerabilities
It was discovered that Perl incorrectly handled certain arguments to
Socket and pack/unpack functions. An attacker could possibly use this
issue to read sensitive information from memory.
(CVE-2026-12087, CVE-2026-57432)
It was discovered that Perl incorrectly handled regular expressions
with a large number of alternation branches. An attacker could
possibly use this issue to cause incorrect matching results.
(CVE-2026-13221)
It was discovered that Perl incorrectly handled certain files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-57433, CVE-2025-15649, CVE-2026-48959, CVE-2026-9538)
It was discovered that Perl incorrectly handled certain inputs. An
attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-48962)
It was discovered that Perl incorrectly handled credential headers
during cross-origin redirects in HTTP::Tiny. An attacker could
possibly use this issue to expose sensitive information.
(CVE-2026-7017)