Security disclosures identified three vulnerabilities in widely used Perl minifier modules, including two denial-of-service flaws in JavaScript::Minifier::XS and a memory leak in CSS::Minifier::XS. CVE-2026-56017 affects JavaScript::Minifier::XS versions before 0.16 and can crash a calling process when the first meaningful token in input is a slash, triggering a NULL pointer dereference and out-of-bounds read through the public minify() API. CVE-2026-56018 also affects versions before 0.16, causing a memory leak on every minify() call that can drive unbounded memory growth in long-lived services that process untrusted or third-party JavaScript.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A security notice disclosed CVE-2026-13593 affecting CSS::Minifier::XS versions before 0.14 for Perl. The flaw is a memory leak in minify() when the entire document is removed during minification, and users were advised to upgrade to version 0.14 or later.
A security notice disclosed CVE-2026-56018 affecting JavaScript::Minifier::XS versions before 0.16 for Perl. The bug causes a memory leak on every call to minify(), enabling unbounded memory growth in long-lived processes, and users were advised to upgrade to version 0.16 or later.
A security notice disclosed CVE-2026-56017 affecting JavaScript::Minifier::XS versions before 0.16 for Perl. The flaw can crash the calling process when the first meaningful token of input is a slash, and users were advised to upgrade to version 0.16 or later.
On 2026-06-28, JavaScript::Minifier::XS version 0.16 was released. The release fixes CVE-2026-56017, a segfault/NULL pointer dereference issue in minify(), and CVE-2026-56018, a memory leak in minify().
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcemetacpan.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.