Vulnerability Description
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Perl | Perl | <= 5.43.9 |
Related Weaknesses (CWE)
References
- https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.paPatch
- https://github.com/Perl/perl5/issues/23388Issue Tracking
- http://www.openwall.com/lists/oss-security/2026/07/13/5Mailing ListPatchThird Party Advisory
FAQ
What is CVE-2026-13221?
CVE-2026-13221 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such ...
How severe is CVE-2026-13221?
CVE-2026-13221 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-13221?
Check the references section above for vendor advisories and patch information. Affected products include: Perl Perl.