Out-of-Bounds Read Vulnerability in Data::ReqRep::Shared by Egor
CVE-2026-59139
Currently unrated
What is CVE-2026-59139?
The Data::ReqRep::Shared library for Perl is susceptible to an out-of-bounds read vulnerability that occurs due to improper validation of request header scalars and array contents. Specifically, the function reqrep_recv_locked performs memory operations based on parameters derived from untrusted sources, resulting in the potential to read memory outside of designated boundaries. This can be exploited by a local attacker with access to modify the backing file, allowing them to manipulate offsets and byte lengths, which may lead to unauthorized memory access or application crashes.
Affected Version(s)
Data::ReqRep::Shared 0 < 0.05
