The CPAN Security Group disclosed two memory-safety vulnerabilities affecting widely used Perl modules. CVE-2026-7040 impacts Text::Minify::XS from v0.3.0 before v0.7.8, where malformed UTF-8 input can trigger a heap overflow in the minify and minify_utf8 functions, leading to heap corruption through improper Unicode handling. Maintainers advised users to upgrade to v0.7.8 or later, and said deployments that cannot patch immediately should validate strings before passing them to the affected routines.
A separate advisory, CVE-2026-7111, affects Text::CSV_XS before 1.62 and stems from a use-after-free when registered callbacks extend the Perl argument stack. The bug arises because methods including Parse, print, getline, and getline_all may retain a stale stack pointer across callback execution, creating a path to type confusion, memory corruption, crashes, or logic errors. The issue does not affect Text::CSV_XS instances that do not use registered callbacks, and the fix was released in version 1.62 after a public patch and CPAN publication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Version 1.62 of Text::CSV_XS was published to CPAN with a fix for CVE-2026-7111. The advisory noted that deployments without registered callbacks were not affected.
CVE-2026-7111 was reserved for the Text::CSV_XS use-after-free vulnerability. The issue can lead to type confusion, memory corruption, logic errors, or crashes when registered callbacks trigger Perl stack reallocation.
A corrected Text::Minify::XS release, version 0.7.8, was uploaded to CPAN to fix CVE-2026-7040. Users were advised to upgrade or validate strings passed to the affected functions as a workaround.
A public patch was committed for CVE-2026-7111 in Text::CSV_XS, addressing a use-after-free caused by callbacks that extend the Perl argument stack. The bug affected methods including parse, print, getline, and getline_all in versions before 1.62.
The CPAN Security Group identified CVE-2026-7040 in Text::Minify::XS, affecting versions from 0.3.0 before 0.7.8. The flaw is a heap overflow triggered by malformed UTF-8 input in the minify and minify_utf8 functions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.