CVE-2026-107373
Received Received - Intake

Use-After-Free in ExtUtils::Typemaps::STL::String Perl Module

Vulnerability report for CVE-2026-107373, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: CPANSec

Description

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses $var = std::string( SvPV_nolen($arg), SvCUR($arg) ) However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first. When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects ExtUtils::Typemaps::STL::String versions before 1.06 for Perl. It involves a typemap issue where the SV length is read before stringifying the argument. The code uses $var = std::string( SvPV_nolen($arg), SvCUR($arg) ), but C++ argument evaluation order is not specified. Some compilers may evaluate SvCUR($arg) first, leading to invalid values if $arg is not a string, causing program aborts or segfaults.

Detection Guidance

To detect this vulnerability, check if your system uses ExtUtils::Typemaps::STL::String versions before 1.06. Run: perl -MCPAN -e 'print $ExtUtils::Typemaps::STL::String::VERSION' to check the installed version.

Impact Analysis

If you use affected versions of ExtUtils::Typemaps::STL::String, your Perl program may crash or segfault when processing non-string arguments. This could lead to denial of service or unexpected termination of applications relying on this module.

Mitigation Strategies

Upgrade ExtUtils::Typemaps::STL::String to version 1.06 or later. Use: cpan ExtUtils::Typemaps::STL::String or cpanm ExtUtils::Typemaps::STL::String to update the module.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107373. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart