Out-of-Bounds Read Vulnerability in Data::RadixTree::Shared by EGOR
CVE-2026-59141
Currently unrated
What is CVE-2026-59141?
The Data::RadixTree::Shared Perl module versions earlier than 0.02 exhibit a significant flaw that allows an out-of-bounds read due to unvalidated node and arena indices in the rdx_find_locked function. This vulnerability compromises the integrity of the software by allowing malicious users with write access to the backing file to manipulate node records while keeping the header valid. When an untrustworthy node is looked up, it may read data from adjacent memory locations, potentially leading to process crashes and unauthorized information disclosure.
Affected Version(s)
Data::RadixTree::Shared 0 < 0.02
