CVE-2026-82560 affects Pod::Text versions prior to 6.1.1 in the podlators distribution for Perl, allowing a remotely initiated attack that causes CPU and memory exhaustion. The flaw was disclosed by the CPAN Security Group on 19 September 2026 and has been rated problematic.
The vulnerability is triggered when a specially crafted POD document uses deeply nested =over directives, driving the calculated margin to the output width and causing the wrap function in lib/Pod/Text.pm to consume excessive resources. No exploit code has been observed in the wild at this time, and the attack vector does not require authentication or local access.
Affected users should upgrade the podlators distribution to version 6.1.1 or later. Systems relying on Perl toolchains to process untrusted POD input, such as documentation build pipelines or package management utilities, carry the most practical risk from this vulnerability.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.
We use analytics cookies to understand how visitors use Deltabridge and improve the site. They’re off until you accept. See our Privacy Policy.