{"id":"AZL-89307","summary":"CVE-2026-48959 affecting package perl for versions less than 5.38.2-512","details":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip-\u003enew($zip, Name =\u003e $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","modified":"2026-08-30T05:26:50Z","published":"2026-05-27T04:16:31Z","upstream":["CVE-2026-48959"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959"}],"affected":[{"package":{"name":"perl","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.38.2-512"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89307.json"}}],"schema_version":"1.9.0"}