Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-59141— Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked

Quick assessment

Affected
EGOR Data::RadixTree::Shared
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

EGOR Data::RadixTree::Shared是EGOR个人开发者的一款共享基数树数据结构的模块产品。 EGOR Data::RadixTree::Shared 0.02之前版本存在缓冲区错误漏洞,该漏洞源于未验证节点和区域索引,导致在rdx_find_locked中出现越界读取,可能读取相邻内存或导致进程崩溃。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.54% · P43

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 1

VendorProduct Version RangeStatus
EGOR Data::RadixTree::Shared < 0.02 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59141

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked
Source: CVE Program / CVE List V5
Vulnerability Description
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts. rdx_find_locked indexes nodes[cur].children[k] and reads each node's label_off and label_len raw from the mmap'd segment, none bounded against the node count or the arena size. A local peer that can write the backing file can leave the header valid while poisoning the node records, so a lookup dereferences an out-of-bounds node or arena index, reading adjacent memory or crashing the process.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
EGOR Data::RadixTree::Shared 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
EGOR Data::RadixTree::Shared是EGOR个人开发者的一款共享基数树数据结构的模块产品。 EGOR Data::RadixTree::Shared 0.02之前版本存在缓冲区错误漏洞,该漏洞源于未验证节点和区域索引,导致在rdx_find_locked中出现越界读取,可能读取相邻内存或导致进程崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
EGOR Data::RadixTree::Shared 0 ~ 0.02 -

II. Public POCs for CVE-2026-59141

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59141

登录查看更多情报信息。

Vendor Pages for CVE-2026-59141 (1)

Other References for CVE-2026-59141 (1)

Same Patch Batch · EGOR · 2026-07-21 · 23 CVEs total

CVE-2026-59143 Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via
CVE-2026-65068 Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backi
CVE-2026-65062 Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing
CVE-2026-65065 Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap bac
CVE-2026-65069 Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backi
CVE-2026-65066 Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backin
CVE-2026-65063 Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing
CVE-2026-65067 Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing fi
CVE-2026-65064 Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing f
CVE-2026-65061 Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing fi
CVE-2026-59147 Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writ
CVE-2026-59140 Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unva
CVE-2026-59145 Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalid
CVE-2026-59146 Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writ
CVE-2026-59144 Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via a
CVE-2026-64613 Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing fi
CVE-2026-64617 Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing fi
CVE-2026-64615 Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing fil
CVE-2026-64614 Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing fil
CVE-2026-64616 Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing f

Showing top 20 of 23 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-59141

No comments yet


Leave a comment