What is CVE-2026-72888?
CVE-2026-72888 is a memory exhaustion vulnerability in Perl's Net::OAuth module before version 0.32, caused by the unbounded caching of failed module loads in the `smart_require` function. It affects applications using Net::OAuth, and updating to version 0.32 or later is the recommended mitigation.
Azərbaycanca: CVE-2026-72888 Perl-in Net::OAuth modulunun 0.32-dən əvvəlki versiyalarında `smart_require` funksiyasının uğursuz modul yükləmələrini limitsiz keşləməsi səbəbindən yaranan yaddaş tükənməsi zəifliyidir. Bu, xüsusilə Net::OAuth istifadə edən tətbiqlərə təsir edir. Net::OAuth modulunu 0.32 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What component does CVE-2026-72888 affect?
CVE-2026-72888 affects Perl's Net::OAuth module before version 0.32, specifically the `smart_require` function.
How can this vulnerability be mitigated?
Updating the Net::OAuth module to version 0.32 or later is the recommended mitigation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.