CVE-2026-80490
Received Received - Intake

Out-of-Bounds Read in Algorithm::AhoCorasick::XS Perl Module

Vulnerability report for CVE-2026-80490, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CPANSec

Description

Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV. When the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process. Note that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl. This can be triggered when the haystack is a numeric value, for example, my $ac = Algorithm::AhoCorasick::XS->new( [ "11", "22" ] ); $ac->matches( 211 ); This can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
richardjharris algorithm_ahocorasick_xs 0.04

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Algorithm::AhoCorasick::XS Perl module versions through 0.04. It occurs when the module reads the length of a haystack string before properly stringifying the input. When the input is a reference, integer, or float, the SvCUR macro returns an invalid length, causing an out-of-bounds read that can crash the process. The issue arises because the evaluation order of arguments to std::string is compiler-dependent, potentially leading to uncatchable aborts in Perl.

Detection Guidance

This vulnerability affects Perl modules using Algorithm::AhoCorasick::XS versions through 0.04. To detect it, check if your system has this module installed by running: perl -MAlgorithm::AhoCorasick::XS -e 'print $Algorithm::AhoCorasick::XS::VERSION' If the version is 0.04 or lower, the system is vulnerable. Additionally, review Perl scripts using this module for inputs that may be numeric, blessed objects, or decoded JSON.

Impact Analysis

This vulnerability can cause crashes or unexpected behavior in Perl applications using Algorithm::AhoCorasick::XS. It may be triggered when processing numeric values, JSON-decoded data, or numeric database columns. For example, passing a number like 211 to the matches method could lead to an out-of-bounds read and process termination.

Mitigation Strategies

Immediately update Algorithm::AhoCorasick::XS to a patched version if available. If no patch exists, avoid using numeric inputs, blessed objects, or decoded JSON as haystack inputs in the module. Replace the module with an alternative implementation that handles inputs safely.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80490. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart