CVE-2026-77781 - Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Brief
CVE ID : CVE-2026-77781
Published : Aug. 22, 2026, 12:16 a. m.
- 53 minutes ago
Description : Tie::Hash::Regex versions before 2.
- 0 for Perl will throw an exception on unparseable lookup keys.
The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions.
Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies.
An application that looks up externally supplied strings in a tied hash will die on an invalid key.
Severity: 0.0
