SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57433

CRITICAL · CVSS 9.8 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A signed integer overflow vulnerability exists in Storable versions prior to 3.41 for Perl, specifically when deserializing crafted SX_HOOK records. This flaw allows an attacker to trigger a panic in the application, leading to a denial of service during the deserialization process. Organizations using affected versions of Storable should prioritize patching this vulnerability due to its critical severity and potential impact on application stability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57433
Severity
CRITICAL
CVSS
9.8
EPSS
0.36%

Original NVD Description

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

Related CVEs

Other vulnerabilities affecting the same vendor(s)