What is CVE-2026-19082?
CVE-2026-19082 is a vulnerability in the Imager module for Perl, affecting versions from 0.45_02 before 1.034. It allows exposure of adjacent heap bytes via a strlen() over-read from zero-count ASCII EXIF entries in the copy_string_tags() function. Users should upgrade to Imager version 1.034 or later.
Azərbaycanca: CVE-2026-19082, Perl üçün Imager modulunun 0.45_02 ilə 1.034 arası versiyalarında aşkarlanmış bir zəiflikdir. Bu boşluq, `copy_string_tags()` funksiyasında ASCII EXIF məlumatlarının səhv hesablanması nəticəsində `strlen()` vasitəsilə bitişik heap yaddaş baytlarının oxunmasına səbəb olur. İstifadəçilərə Imager modulunu 1.034 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which software module is affected by CVE-2026-19082?
This vulnerability affects the Imager module for Perl.
To which version should the Imager module be upgraded to mitigate CVE-2026-19082?
The Imager module should be upgraded to version 1.034 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.