Red Hat released security updates for perl-Date-Manip to address CVE-2026-60075, an Important denial-of-service flaw in Date::Manip for Perl. The bug stems from inefficient regular-expression processing in the _parse_time function, where quadratic backtracking in an unanchored time substitution can let attackers send long whitespace-heavy strings that trigger excessive CPU consumption even when no valid time is present. Applications that pass untrusted, unbounded input to ParseDate(), Date::Manip::Date->parse(), or ->parse_time() are exposed to service degradation or loss of availability.
The fixes were issued for Red Hat Enterprise Linux 9 and 10 in advisories RHSA-2026:56970 and RHSA-2026:56971, with updated perl-Date-Manip packages 6.85-3.el9_8.1 and 6.94-5.el10_2.1 respectively, covering multiple architectures and support channels. Additional downstream and related notices indicate affected packages in Oracle Linux 10 and RHEL 8, and the weakness aligns with CWE-1333 for inefficient regular expression complexity, a class commonly associated with Regular Expression Denial of Service (ReDoS). No known public exploits were listed in the referenced advisories at publication time.

See affected versions and whether adversaries are exploiting it.
15 events from the most recent confirmed update back to the earliest known activity.
A Miracle Linux 9 security advisory identified as AXSA-2026-1643 was published for perl-date-manip to address CVE-2026-60075. The notice described the issue as a denial-of-service vulnerability with high availability impact and stated that no known exploits were available.
A Miracle Linux 8 security advisory identified as AXSA-2026-1619 was published for perl-date-manip to address CVE-2026-60075. The notice described the issue as a denial-of-service vulnerability with high availability impact and stated that no known exploits were available.
An Oracle Linux 9 security advisory identified as ELSA-2026-56970 was published for perl-date-manip to address CVE-2026-60075. The notice described the issue as availability-impacting and stated that no known exploits were available at publication time.
A Rocky Linux 8 security advisory for perl-Date-Manip, tracked in Nessus as rocky_linux_RLSA-2026-57562.nasl, addressed CVE-2026-60075. The notice described the issue as availability-impacting and stated that no known exploits were available.
An AlmaLinux 8 security advisory identified as ALSA-2026:57562 was published for perl-Date-Manip to address CVE-2026-60075 across multiple AlmaLinux 8 repositories. The notice described the issue as a denial-of-service vulnerability with high availability impact and stated that no known exploits were available.
An Oracle Linux 8 security advisory identified as ELSA-2026-57562 was published for perl-Date-Manip to address CVE-2026-60075. The notice described the issue as a denial-of-service vulnerability with high availability impact and stated that no known exploits were available.
A Rocky Linux 10 security advisory for perl-Date-Manip, tracked in Nessus as rocky_linux_RLSA-2026-56971.nasl, addressed CVE-2026-60075. The notice described the issue as having high availability impact and stated that no known exploits were available.
A Rocky Linux 9 security advisory for perl-Date-Manip, tracked in Nessus as rocky_linux_RLSA-2026-56970.nasl, addressed CVE-2026-60075. The notice described the issue as having high availability impact and stated that no known exploits were available.
A Red Hat Enterprise Linux 8 advisory, RHSA-2026:57562, was published for perl-Date-Manip to address CVE-2026-60075. The notice classified the issue as Important and recommended updating affected packages.
An AlmaLinux 9 security advisory identified as ALSA-2026:56970 was published for perl-Date-Manip to address CVE-2026-60075 across multiple AlmaLinux 9 repositories. The notice described the issue as a denial-of-service vulnerability with high availability impact and stated that no known exploits were available.
An AlmaLinux 10 security advisory identified as ALSA-2026:56971 was published for perl-Date-Manip to address CVE-2026-60075 across multiple AlmaLinux 10 repositories. The notice described the issue as a denial-of-service vulnerability with high availability impact and stated that no known exploits were available.
An Oracle Linux 10 security advisory identified as ELSA-2026-56971 was published for perl-date-manip, covering CVE-2026-60075. The notice described the issue as availability-impacting and stated that no known exploits were available at publication time.
Red Hat published advisory RHSA-2026:56971 for Red Hat Enterprise Linux 10, rating the issue Important and releasing perl-Date-Manip-6.94-5.el10_2.1 to fix the vulnerability. The update covers multiple RHEL 10 variants, architectures, and lifecycle channels.
Red Hat published advisory RHSA-2026:56970 for Red Hat Enterprise Linux 9, rating the issue Important and releasing perl-Date-Manip-6.85-3.el9_8.1 to remediate the denial-of-service flaw. The advisory applies across multiple RHEL 9 architectures and support channels.
The vulnerability CVE-2026-60075 was published as a denial-of-service issue in Date::Manip for Perl caused by CPU exhaustion during date parsing. Later advisories and plugin entries reference this publication date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.