Skip to main content
Version: v1.1.x

CVE-2026-8376

CVE Details

Visit the official vulnerability details page for CVE-2026-8376 to learn more.

Initial Publication

05/26/2026

Last Update

05/27/2026

Third Party Dependency

perl

NIST CVE Summary

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.

Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.

A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.

CVE Severity

7.3

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Modified

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.3⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.