top of page
perceptive_background_267k.jpg

Sereal::Encoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library.

Sereal::Encoder embeds a vers…

Published:

30 maart 2026 om 22:00:00

Alert date:

31 maart 2026 om 17:08:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

Sereal::Encoder versions 4.000 through 4.009_002 for Perl contains a buffer overwrite vulnerability in its embedded Zstandard compression library. The flaw is linked to CVE-2019-11922, a race condition in Zstandard versions prior to 1.3.8 that affects one-pass compression functions. Attackers can exploit this vulnerability to write bytes out of bounds when output buffers smaller than recommended size are used. This represents a supply chain security issue where an older vulnerable dependency creates security risks in newer software versions.

Technical details

Mitigation steps:

Affected products:

Sereal::Encoder
Zstandard library

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page