{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "perl"
   ],
   "cvss": 9.8,
   "distro_severity": "critical",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "CVE-2026-8376",
   "severity": "critical",
   "title": "Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8376"
  },
  {
   "affects": [
    "perl"
   ],
   "cvss": 9.1,
   "distro_severity": "critical",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "CVE-2026-13221",
   "severity": "critical",
   "title": "Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13221"
  },
  {
   "affects": [
    "perl"
   ],
   "cvss": 8.4,
   "distro_severity": "high",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "CVE-2026-57432",
   "severity": "high",
   "title": "Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57432"
  },
  {
   "affects": [
    "perl"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "5.41.13"
   ],
   "id": "CVE-2025-40909",
   "severity": "medium",
   "title": "Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone\u2026",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40909"
  },
  {
   "affects": [
    "perl"
   ],
   "cvss": 5.7,
   "distro_severity": "medium",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "CVE-2026-15534",
   "severity": "medium",
   "title": "Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15534"
  },
  {
   "affects": [
    "perl"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "5.41.9"
   ],
   "id": "CVE-2026-19487",
   "severity": "medium",
   "title": "Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19487"
  }
 ],
 "findings_changed_at": "2026-08-26T18:15:06Z",
 "image": "perl",
 "inputs": {
  "sbom_sha256": "440bd1489ee7d2722301a89f5ff5a82156a488c7a9a910bf928e03fecb800855"
 },
 "platform_digest": "sha256:b8de564e7521d3ddf934c693465b173891519ff0c8ce4266c2871a6dd6c34236",
 "project": "perl",
 "receipt_sha256": "a38dc1ed9f25d1c6d25f432dbd9afcfa8a7b44755f2d2e110b0f17b994b73d5b",
 "scanner": "grype",
 "severity_counts": {
  "critical": 2,
  "high": 1,
  "low": 0,
  "medium": 3,
  "unknown": 0
 },
 "suppressed": [],
 "version": "5.40.5",
 "vex_applied": [
  "perl-5.40.5-arm64.vex.json",
  "perl-5.40.5-arm64.ubuntu-vex.json"
 ]
}
