What is CVE-2026-60075?
CVE-2026-60075 affects Date::Manip versions through 6.99 for Perl, allowing CPU exhaustion via quadratic backtracking in the _parse_time function's unanchored time substitution. Users should update to the latest version to mitigate this issue.
Azərbaycanca: CVE-2026-60075, Perl üçün Date::Manip modulunun 6.99 və əvvəlki versiyalarında aşkar edilib. Bu zəiflik, _parse_time funksiyasındakı lövbərsiz nümunə uyğunlaşdırma zamanı yaranan quadratic backtracking səbəbilə CPU-nun həddindən artıq yüklənməsinə gətirib çıxarır. Təsirə məruz qalmamaq üçün modulu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of Date::Manip are affected by CVE-2026-60075?
This vulnerability affects Date::Manip versions through 6.99.
How can I mitigate the CVE-2026-60075 vulnerability?
Users should update the Date::Manip module to the latest version to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.