Memory Exhaustion Flaw in ExtUtils::Typemaps::STL::List for Perl
CVE-2026-107794

Currently unrated

Key Information:

Vendor

Perl

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-107794?

A vulnerability in ExtUtils::Typemaps::STL::List for Perl prior to version 1.07 leads to a significant memory exhaustion issue. When an empty list is processed, the system attempts to allocate a 32 GiB array on the backend. This results in the potential for a denial of service due to memory exhaustion, as the array exceeds manageable limits. Earlier fixes addressed similar problems in related types, emphasizing the importance of staying updated on version releases.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.