Array Reference Vulnerability in XS::Parse::Infix for Perl
CVE-2026-85644

Currently unrated

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-85644?

A flaw exists in XS::Parse::Infix versions from 0.40 to 0.49 in Perl, where the function improperly validates numeric inputs as array references. This oversight allows attackers to manipulate input structures, leading to potential segmentation faults or arbitrary code execution through crafted strings. The vulnerability arises from misuse of reference checks, allowing unauthorized memory access when the interpreter dereferences an invalid input address. This can lead to severe instability in applications utilizing this feature, especially when handling dynamic input such as JSON.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.