What is CVE-2026-60074?
CVE-2026-60074 affects Date::Manip Perl module versions through 6.99, where non-ASCII decimal digits can pass numeric range checks but cause corrupted date outputs due to the `\d` regex shorthand matching Unicode decimal digits. Users should update to the latest patched version or sanitize inputs to mitigate the issue.
Azərbaycanca: CVE-2026-60074, Perl üçün Date::Manip modulunun 6.99-dək versiyalarında aşkar edilmişdir. Bu zəiflik, qeyri-ASCII decimal rəqəmləri emal zamanı tarix analiz funksiyalarının səhv nəticələr qaytarmasına səbəb olur. İstifadəçilər təhlükəsizlik yaması tətbiq edilənə qədər modulun son versiyasına yeniləməli və ya daxil edilən məlumatları yoxlamalıdır.
FAQ2
Which versions of the Date::Manip module are affected by CVE-2026-60074?
This vulnerability affects Date::Manip module versions through 6.99.
What should users do to mitigate the CVE-2026-60074 vulnerability?
Users should update to the latest patched version of the module or sanitize inputs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.