Out-of-Bounds Read Vulnerability in Data::RadixTree::Shared by EGOR
CVE-2026-59141

Currently unrated

Key Information:

Vendor

Egor

Vendor
CVE Published:
21 July 2026

What is CVE-2026-59141?

The Data::RadixTree::Shared Perl module versions earlier than 0.02 exhibit a significant flaw that allows an out-of-bounds read due to unvalidated node and arena indices in the rdx_find_locked function. This vulnerability compromises the integrity of the software by allowing malicious users with write access to the backing file to manipulate node records while keeping the header valid. When an untrustworthy node is looked up, it may read data from adjacent memory locations, potentially leading to process crashes and unauthorized information disclosure.

Affected Version(s)

Data::RadixTree::Shared 0 < 0.02

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.