CyberRota Analysis
AI-GeneratedString::Util versions prior to 1.36 for Perl are vulnerable to a regular expression denial of service due to the greedy matching behavior of the trim and rtrim functions, which can lead to CPU exhaustion when processing untrusted input containing long runs of whitespace. This vulnerability can be exploited by attackers to degrade application performance, making it critical for developers and system administrators using affected versions to prioritize updates. Immediate action is recommended to mitigate potential service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the match at each offset of a long whitespace run, producing quadratic backtracking. The fix replaces \s*$ with \s+$. Any caller that passes untrusted input to trim or rtrim can trigger CPU exhaustion with a string containing a long run of whitespace.