<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:13:39 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:56970 — Important: perl-Date-Manip security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:56970</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: perl-Date-Manip&lt;/p&gt;
&lt;p&gt;Date::Manip is a series of modules designed to make any common date/time operation easy to do. Operations such as comparing two times, determining a data a given amount of time from another, or parsing international times are all easily done. It deals with time as it is used in the Gregorian calendar (the one currently in use) with full support for time changes due to daylight saving time.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-Date-Manip: Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing (CVE-2026-60075)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: perl-Date-Manip&lt;/p&gt;
&lt;p&gt;Date::Manip is a series of modules designed to make any common date/time operation easy to do. Operations such as comparing two times, determining a data a given amount of time from another, or parsing international times are all easily done. It deals with time as it is used in the Gregorian calendar (the one currently in use) with full support for time changes due to daylight saving time.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-Date-Manip: Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing (CVE-2026-60075)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:56970</guid>
    </item>
    <item>
      <title>EUVD-2026-362923</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362923</link>
      <description>EUVD-2026-362923</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362923</guid>
    </item>
    <item>
      <title>fkie_cve-2026-60075</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-60075</link>
      <description>&lt;p&gt;Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time.&lt;/p&gt;
&lt;p&gt;_parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes.&lt;/p&gt;
&lt;p&gt;Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date-&amp;gt;parse() or -&amp;gt;parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time.&lt;/p&gt;
&lt;p&gt;_parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes.&lt;/p&gt;
&lt;p&gt;Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date-&amp;gt;parse() or -&amp;gt;parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-60075</guid>
    </item>
    <item>
      <title>GHSA-6w78-p685-p2f6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6w78-p685-p2f6</link>
      <description>&lt;p&gt;Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time.&lt;/p&gt;
&lt;p&gt;_parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes.&lt;/p&gt;
&lt;p&gt;Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date-&amp;gt;parse() or -&amp;gt;parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time.&lt;/p&gt;
&lt;p&gt;_parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes.&lt;/p&gt;
&lt;p&gt;Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date-&amp;gt;parse() or -&amp;gt;parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6w78-p685-p2f6</guid>
    </item>
    <item>
      <title>OESA-2026-3539 — perl-Date-Manip security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3539</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: perl-Date-Manip, openEuler:22.03-LTS-SP4: perl-Date-Manip, openEuler:24.03-LTS-SP1: perl-Date-Manip, openEuler:24.03-LTS-SP3: perl-Date-Manip, openEuler:24.03-LTS-SP4: perl-Date-Manip&lt;/p&gt;
&lt;p&gt;Date::Manip is a series of modules designed to make any common date/time operation easy to do. Operations such as comparing two times,determining a date a given amount of time from another, or parsing international times are all easily done. It deals with time as it is used in the Gregorian calendar (the one currently in use) with full support for time changes due to daylight saving time. From the very beginning, the main focus of Date::Manip has been to be able to do ANY desired date/time operation easily.Many other modules exist which may do a subset of these operations quicker or more efficiently,but no other module can do all of the operations available in Date::Manip. Date::Manip has functionality to work with several fundamental types of data.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check.&lt;/p&gt;
&lt;p&gt;The parse regexes capture year, month and day with the \d shorthand, which on a character string matches the whole Unicode decimal digit property \p{Nd} and not just [0-9]. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone ($y&amp;amp;lt;1 || $y&amp;amp;gt;9999, $m&amp;amp;lt;1 || $m&amp;amp;gt;12, $d&amp;amp;lt;1 || $d&amp;amp;gt;$days), and _parse_check stores the numified fields ($y+0). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: perl-Date-Manip, openEuler:22.03-LTS-SP4: perl-Date-Manip, openEuler:24.03-LTS-SP1: perl-Date-Manip, openEuler:24.03-LTS-SP3: perl-Date-Manip, openEuler:24.03-LTS-SP4: perl-Date-Manip&lt;/p&gt;
&lt;p&gt;Date::Manip is a series of modules designed to make any common date/time operation easy to do. Operations such as comparing two times,determining a date a given amount of time from another, or parsing international times are all easily done. It deals with time as it is used in the Gregorian calendar (the one currently in use) with full support for time changes due to daylight saving time. From the very beginning, the main focus of Date::Manip has been to be able to do ANY desired date/time operation easily.Many other modules exist which may do a subset of these operations quicker or more efficiently,but no other module can do all of the operations available in Date::Manip. Date::Manip has functionality to work with several fundamental types of data.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check.&lt;/p&gt;
&lt;p&gt;The parse regexes capture year, month and day with the \d shorthand, which on a character string matches the whole Unicode decimal digit property \p{Nd} and not just [0-9]. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone ($y&amp;amp;lt;1 || $y&amp;amp;gt;9999, $m&amp;amp;lt;1 || $m&amp;amp;gt;12, $d&amp;amp;lt;1 || $d&amp;amp;gt;$days), and _parse_check stores the numified fields ($y+0). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3539</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11457-1 — perl-Date-Manip-6.990.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11457-1</link>
      <description>&lt;p&gt;perl-Date-Manip-6.990.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-Date-Manip-6.990.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11457-1</guid>
    </item>
    <item>
      <title>RLSA-2026:56970 — Important: perl-Date-Manip security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:56970</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: perl-Date-Manip&lt;/p&gt;
&lt;p&gt;Date::Manip is a series of modules designed to make any common date/time operation easy to do. Operations such as comparing two times, determining a data a given amount of time from another, or parsing international times are all easily done. It deals with time as it is used in the Gregorian calendar (the one currently in use) with full support for time changes due to daylight saving time.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-Date-Manip: Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing (CVE-2026-60075)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: perl-Date-Manip&lt;/p&gt;
&lt;p&gt;Date::Manip is a series of modules designed to make any common date/time operation easy to do. Operations such as comparing two times, determining a data a given amount of time from another, or parsing international times are all easily done. It deals with time as it is used in the Gregorian calendar (the one currently in use) with full support for time changes due to daylight saving time.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-Date-Manip: Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing (CVE-2026-60075)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:56970</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23218-1 — Security update for perl-Date-Manip</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23218-1</link>
      <description>&lt;p&gt;Security update for perl-Date-Manip&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for perl-Date-Manip&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23218-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-60075</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-60075</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libdate-manip-perl, Ubuntu:16.04:LTS: libdate-manip-perl, Ubuntu:18.04:LTS: libdate-manip-perl, Ubuntu:20.04:LTS: libdate-manip-perl, Ubuntu:22.04:LTS: libdate-manip-perl, Ubuntu:24.04:LTS: libdate-manip-perl, Ubuntu:26.04:LTS: libdate-manip-perl&lt;/p&gt;
&lt;p&gt;Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes. Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date-&amp;gt;parse() or -&amp;gt;parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libdate-manip-perl, Ubuntu:16.04:LTS: libdate-manip-perl, Ubuntu:18.04:LTS: libdate-manip-perl, Ubuntu:20.04:LTS: libdate-manip-perl, Ubuntu:22.04:LTS: libdate-manip-perl, Ubuntu:24.04:LTS: libdate-manip-perl, Ubuntu:26.04:LTS: libdate-manip-perl&lt;/p&gt;
&lt;p&gt;Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes. Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date-&amp;gt;parse() or -&amp;gt;parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-60075</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2937 — Perl: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2937</link>
      <description>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in Perl ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in Perl ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2937</guid>
    </item>
  </channel>
</rss>
