CVE-2026-7040

HIGH

Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters

Title source: cna
STIX 2.1

Description

Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters. The minify functions mishandled some malformed UTF-8 characters, leading to heap corruption. Note that the minify_utf8 function is an alias for minify.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 11.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-122 CWE-176
Status published
Products (2)
RRWO/Text::Minify::XS 0.3.0 - 0.7.8
RRWO/Text::Minify::XS v0.3.0 - v0.7.8
Published Apr 27, 2026
Tracked Since Apr 27, 2026