← All briefs
Brief·2 sources19 Sept 2026

CVE-2026-82560 Exposes Perl Pod::Text To Resource Exhaustion Attack

vulnerability-disclosurepatch-management

Summary

CVE-2026-82560 affects Pod::Text versions prior to 6.1.1 in the podlators distribution for Perl, allowing a remotely initiated attack that causes CPU and memory exhaustion. The flaw was disclosed by the CPAN Security Group on 19 September 2026 and has been rated problematic.

The vulnerability is triggered when a specially crafted POD document uses deeply nested =over directives, driving the calculated margin to the output width and causing the wrap function in lib/Pod/Text.pm to consume excessive resources. No exploit code has been observed in the wild at this time, and the attack vector does not require authentication or local access.

Affected users should upgrade the podlators distribution to version 6.1.1 or later. Systems relying on Perl toolchains to process untrusted POD input, such as documentation build pipelines or package management utilities, carry the most practical risk from this vulnerability.

Timeline

  1. 19 September 2026
    CVE-2026-82560 Disclosed via CPAN Security Group Advisory
    The CPAN Security Group published details of CVE-2026-82560 to the oss-security mailing list, identifying the vulnerability in Pod::Text versions before 6.1.1 and recommending upgrade to the fixed release.
  2. 19 September 2026
    VulDB Entry Published For CVE-2026-82560
    VulDB catalogued the vulnerability, rating it as problematic and confirming remote initiation is possible, with no exploit currently available.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.

CVE-2026-82560 Exposes Perl Pod::Text To Resource Exhaustion Attack | Deltabridge