What is CVE-2026-59147?
This vulnerability affects Data::DisjointSet::Shared Perl module versions before 0.02, allowing out-of-bounds reads and writes via an unvalidated parent index in the `dsu_find` function. While the `dsu_validate_header` function checks header scalars and region layout, it fails to validate the array contents. Users should upgrade to version 0.02 or later to mitigate the issue.
Azərbaycanca: Bu zəiflik Perl-in Data::DisjointSet::Shared modulunun 0.02 versiyasından əvvəlki versiyalarında aşkarlanıb. `dsu_find` funksiyasında doğrulanmamış valideyn indeksi səbəbindən massiv sərhədlərindən kənar oxuma və yazma əməliyyatları baş verə bilər. Bu problemdən qorunmaq üçün modulu 0.02 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ1
Which versions of the Data::DisjointSet::Shared module are affected by this vulnerability?
The vulnerability affects Data::DisjointSet::Shared Perl module versions before 0.02.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.