OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-85644

HIGH · CVSS 7.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The XS::Parse::Infix module in Perl versions 0.40 to 0.49 is vulnerable due to improper validation of array references, allowing an attacker to craft input that can lead to a segmentation fault and potential arbitrary code execution. This vulnerability arises when the module incorrectly interprets numbers as array references, enabling exploitation through specially crafted strings. Developers and organizations using these versions of XS::Parse::Infix should prioritize patching or upgrading to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
proof-of-concept

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85644
Severity
HIGH
CVSS
7.5
EPSS
0.39%

Original NVD Description

XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it tests using SvRV() rather than SvROK(). SvRV() reads a union slot that only holds a referent once SvROK(sv) is true, so the guard never validates that it is a reference. For an IV or NV that slot holds the number itself, SvRV() returns the caller's value and SvTYPE() dereferences it at offset 12. This will generally result in a segmentation fault. An application that hands the wrapper a list built from decoded input (for example, from JSON) lets whoever supplies a number in that list choose the address that the interpreter dereferences. An ordinary string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but an attacker-crafted string carrying 0x0b there passes, and the buffer is then used as an AV head, with AvARRAY taken from bytes 16-23 and its entries pushed onto the Perl stack as live SVs. A simple proof-of-concept uses the zip operator: use Syntax::Operator::Zip 'zip'; my @args = ([1], 2); zip(@args);