Back to overview

CVE-2026-8507

CRITICAL
9.8
CVSS 3.1
Description
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew().

Metadata

CVE ID
CVE-2026-8507
State
PUBLISHED
Assigner
CPANSec
Reserved
2026-05-13 22:45 UTC
Published
2026-05-17 18:43 UTC
Last updated
2026-05-18 12:55 UTC
Primary CWE
CWE-787
CWE-787 Out-of-bounds Write
Vendor / Product
JONASBN / Crypt::OpenSSL::PKCS12
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
JONASBN Crypt::OpenSSL::PKCS12 0 ≤ 1.94
Weakness (CWE)
CWESourceDescription
CWE-787 cna CWE-787 Out-of-bounds Write
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview