CPANSA-Algorithm-AhoCorasick-XS-2026-80490: Algorithm-AhoCorasick-XS vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2026-09-30T00:00:00 Engine CSAF Perl Toolkit 0.26
Current release date 2026-09-30T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score Severity
Original language Language en
Also referred to

Vulnerability Description

Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified.

The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV.

When the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process.

Note that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl.

This can be triggered when the haystack is a numeric value, for example,

my $ac = Algorithm::AhoCorasick::XS->new( [ "11", "22" ] );
$ac->matches( 211 );

This can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.

Vulnerabilities

CVE-2026-80490

Vulnerability Description

Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified.

The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV.

When the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process.

Note that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl.

This can be triggered when the haystack is a numeric value, for example,

my $ac = Algorithm::AhoCorasick::XS->new( [ "11", "22" ] );
$ac->matches( 211 );

This can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.

Weakness CWE-125 : Out-of-bounds Read

Product status

Known affected
Product Score
Algorithm-AhoCorasick-XS greater than 0
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Wed Sep 30 00:00:00 2026 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/