Security advisories disclosed CVE-2024-14031 and CVE-2024-14030 in the Perl packages Sereal::Encoder and Sereal::Decoder, affecting versions 4.000 through 4.009_002. Both modules embed a vulnerable version of the Zstandard (zstd) library and inherit CVE-2019-11922, a buffer overwrite flaw in one-pass compression functions present in zstd versions prior to 1.3.8.
The underlying issue is a race condition that can trigger out-of-bounds writes when an undersized output buffer is used, and the advisories classify the exposure as CWE-1395: dependency on a vulnerable third-party component. Maintainers advised users to upgrade both Perl modules to version 4.010 or later to remove the vulnerable bundled library.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A security advisory disclosed CVE-2024-14031 affecting Sereal::Encoder for Perl versions 4.000 through 4.009_002. The flaw was traced to an embedded vulnerable Zstandard library version affected by CVE-2019-11922, and users were advised to upgrade to version 4.010 or later.
A CPAN Security Group advisory disclosed CVE-2024-14030 affecting Sereal::Decoder for Perl versions 4.000 through 4.009_002. The issue stems from an embedded vulnerable Zstandard library version affected by CVE-2019-11922, and users were advised to upgrade to version 4.010 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.