CVE-2026-107373
Received
Received - Intake
Use-After-Free in ExtUtils::Typemaps::STL::String Perl Module
Vulnerability report for CVE-2026-107373, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-10
Last updated on: 2026-10-10
Assigner: CPANSec
Description
Description
ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.
The typemap uses
$var = std::string( SvPV_nolen($arg), SvCUR($arg) )
However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.
When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |