Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-13221— Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk

Quick assessment

Affected
CVE-2026-13221
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SHAY perl是SHAY的编程语言解释器。 SHAY perl 5.43.9及之前版本存在数字错误漏洞,该漏洞源于在Perl_study_chunk中将超过65535个固定字符串分支编译为trie时,分支计数溢出16位字段导致trie匹配决策表截断,可能产生误报和漏报的正则表达式匹配结果。

AI Predicted 7.4 Difficulty: Moderate EPSS 0.43% · P36

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 3

VendorProduct Version RangeStatus
None None < 5.40.5-RC1 affected
5.41.0< 5.42.3-RC1 affected
5.43.0< 5.43.10 affected

I. Basic Information for CVE-2026-13221

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
Source: CVE Program / CVE List V5
Vulnerability Description
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5
Vulnerability Title
SHAY perl 数字错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SHAY perl是SHAY的编程语言解释器。 SHAY perl 5.43.9及之前版本存在数字错误漏洞,该漏洞源于在Perl_study_chunk中将超过65535个固定字符串分支编译为trie时,分支计数溢出16位字段导致trie匹配决策表截断,可能产生误报和漏报的正则表达式匹配结果。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 5.40.5-RC1 -

II. Public POCs for CVE-2026-13221

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13221

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-13221 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-13221

No comments yet


Leave a comment