Back to overview

CVE-2026-13593

MEDIUM
6.5
CVSS 3.1
Description
CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when processing a document containing only characters to be removed, such as comments and whitespace.

Metadata

CVE ID
CVE-2026-13593
State
PUBLISHED
Assigner
CPANSec
Reserved
2026-06-29 06:55 UTC
Published
2026-06-29 19:37 UTC
Last updated
2026-06-29 22:24 UTC
Primary CWE
CWE-401
CWE-401 Missing Release of Memory after Effective Lifetime
Vendor / Product
GTERMARS / CSS::Minifier::XS
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
GTERMARS CSS::Minifier::XS 0 < 0.14
Weakness (CWE)
CWESourceDescription
CWE-401 cna CWE-401 Missing Release of Memory after Effective Lifetime
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.5 MEDIUM 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Back to overview