Vulnerability Description
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jv | Harfbuzz\ | < 0.032, \ |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2429296Third Party Advisory
- https://metacpan.org/release/JV/HarfBuzz-Shaper-0.032/changesProductRelease Notes
- https://www.cve.org/CVERecord?id=CVE-2026-22693VDB EntryThird Party Advisory
FAQ
What is CVE-2026-0943?
CVE-2026-0943 is a vulnerability with a CVSS score of 7.5 (HIGH). HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.ta...
How severe is CVE-2026-0943?
CVE-2026-0943 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-0943?
Check the references section above for vendor advisories and patch information. Affected products include: Jv Harfbuzz\.