CPANSA-HTTP-Date-2026-14741: HTTP-Date vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-07-17T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-07-17T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | Severity | ||
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next to each other before a trailing `\s*$` anchor. A valid date prefix followed by a long interior run of digits, letters, or whitespace and a single trailing byte that defeats the final match forces the engine to repartition the run, giving polynomial (about quadratic) backtracking. A header value of a few tens of kilobytes runs for tens of seconds of CPU. HTTP::Date parses timestamps such as HTTP `Date`, `Expires`, and `Last-Modified` headers, which commonly originate from untrusted sources. Any caller that passes an untrusted date header to str2time() or parse_date() can be driven to consume unbounded CPU, a denial of service.
Vulnerabilities
CVE-2026-14741
Vulnerability DescriptionHTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date.
parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next to each other before a trailing `\s*$` anchor. A valid date prefix followed by a long interior run of digits, letters, or whitespace and a single trailing byte that defeats the final match forces the engine to repartition the run, giving polynomial (about quadratic) backtracking. A header value of a few tens of kilobytes runs for tens of seconds of CPU.
HTTP::Date parses timestamps such as HTTP `Date`, `Expires`, and `Last-Modified` headers, which commonly originate from untrusted sources. Any caller that passes an untrusted date header to str2time() or parse_date() can be driven to consume unbounded CPU, a denial of service.
| Weakness | CWE-1333 : Inefficient Regular Expression Complexity |
|---|
Product status
Known affected
| Product | Score | ||||
|---|---|---|---|---|---|
| HTTP-Date less than 6.08 |
|
Fixed
- HTTP-Date greater than or equal 6.08
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-HTTP-Date-2026-14741 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-http-date-2026-14741.json - https://github.com/libwww-perl/HTTP-Date/commit/78c20952cdfbf11e03cf1199ad70f13298a84c5c.patch external
https://github.com/libwww-perl/HTTP-Date/commit/78c20952cdfbf11e03cf1199ad70f13298a84c5c.patch - https://github.com/libwww-perl/HTTP-Date/pull/33 external
https://github.com/libwww-perl/HTTP-Date/pull/33 - https://metacpan.org/release/OALDERS/HTTP-Date-6.08/changes external
https://metacpan.org/release/OALDERS/HTTP-Date-6.08/changes - http://www.openwall.com/lists/oss-security/2026/07/17/10 external
http://www.openwall.com/lists/oss-security/2026/07/17/10 - CVE-2026-14741 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-14741
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Fri Jul 17 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/