Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19487— Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass

Quick assessment

Affected
CVE-2026-19487
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述信息的中文翻译: 在 Perl 5.9.4 至 5.41.9 版本之前的代码中,当“失效标志位(failure flag)”处于陈旧状态并导致 函数中的 Aho-Corasick 预扫描过程提前结束时,正则表达式匹配结果会出现错误。 预扫描过程会在主题字符串(subject)中遍历,寻找完整模式可能匹配的位置,并且引擎会尝试从最早记录的位置开始匹配。当发生失败的状态转换时,会设置失效标志位;而后续的成功状态转换却不会清除该标志位。因此,预扫描过程会将该陈旧的标志位误读为失败信号,从而提前终止扫描,

AI Predicted 5.3 Difficulty: Moderate EPSS 0.42% · P34

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
None None 5.9.4< 5.41.9 affected

I. Basic Information for CVE-2026-19487

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
Source: CVE Program / CVE List V5
Vulnerability Description
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds. Example: "ABCDE" =~ m/ABCF|BCDE|C/; # matches C at offset 2, not BCDE "ABCDE" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
控制流实现总是不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 5.9.4 ~ 5.41.9 -

II. Public POCs for CVE-2026-19487

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19487

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-19487 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19487

No comments yet


Leave a comment