VDB
CVE-2026-49146
CVE-2026-49146
PUBLISHED
CVSS 7.5 HIGH
Reported by CPANSec · Published July 8, 2026
App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The -B and -C context options accepted any positive integer, and ack sized the before-context buffer to that value, so a project .ackrc setting --before-context=100000000 made ack allocate a buffer of 100 million elements. A project .ackrc committed to an untrusted repository can abort ack with an out-of-memory condition.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PETDANCE | App::Ack | 0 |
| PETDANCE | App::Ack | 0 |
| alpine | ack | 0, 0, 0 |
Timeline
- Jun 8, 2026 CVE Published
- Jul 8, 2026 CVE Updated
- Jul 9, 2026 EPSS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 28, 2026 Security Advisory
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
References
- patch
- release-notes
- http://www.openwall.com/lists/oss-security/2026/07/08/8 url