CVE-2026-59141: CWE-125 Out-of-bounds Read in EGOR Data::RadixTree::Shared
Data::RadixTree::Shared versions before 0.02 for Perl contain an out-of-bounds read vulnerability due to improper validation of node and arena indices in the rdx_find_locked function. This flaw allows a local attacker who can modify the backing file to cause the software to read memory out-of-bounds or crash. The vulnerability arises because the header validation does not verify node records, leading to unsafe indexing into memory-mapped data structures.
AI Analysis
Technical Summary
CVE-2026-59141 is an out-of-bounds read vulnerability in Data::RadixTree::Shared versions prior to 0.02 for Perl. The vulnerability occurs in the rdx_find_locked function, which indexes node children and reads label offsets and lengths directly from a memory-mapped segment without bounds checking against node counts or arena sizes. Although the header scalars and region layout are validated at attach time, the node records themselves are not validated, allowing a local attacker with write access to the backing file to poison node records. This can cause out-of-bounds memory reads or process crashes when lookups dereference invalid node or arena indices.
Potential Impact
An attacker with local write access to the backing file can exploit this vulnerability to cause out-of-bounds memory reads or crash the process using the Data::RadixTree::Shared module. The CVSS score of 9.1 indicates critical severity with high confidentiality impact and high availability impact, but no integrity impact. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local write access to the backing file used by Data::RadixTree::Shared to trusted users only to prevent poisoning of node records. Monitor for vendor updates regarding an official patch or workaround.
CVE-2026-59141: CWE-125 Out-of-bounds Read in EGOR Data::RadixTree::Shared
Description
Data::RadixTree::Shared versions before 0.02 for Perl contain an out-of-bounds read vulnerability due to improper validation of node and arena indices in the rdx_find_locked function. This flaw allows a local attacker who can modify the backing file to cause the software to read memory out-of-bounds or crash. The vulnerability arises because the header validation does not verify node records, leading to unsafe indexing into memory-mapped data structures.
CVSS v3.1
Score 9.1critical
Affected software
pkg:github/Data-RadixTree-SharedRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59141 is an out-of-bounds read vulnerability in Data::RadixTree::Shared versions prior to 0.02 for Perl. The vulnerability occurs in the rdx_find_locked function, which indexes node children and reads label offsets and lengths directly from a memory-mapped segment without bounds checking against node counts or arena sizes. Although the header scalars and region layout are validated at attach time, the node records themselves are not validated, allowing a local attacker with write access to the backing file to poison node records. This can cause out-of-bounds memory reads or process crashes when lookups dereference invalid node or arena indices.
Potential Impact
An attacker with local write access to the backing file can exploit this vulnerability to cause out-of-bounds memory reads or crash the process using the Data::RadixTree::Shared module. The CVSS score of 9.1 indicates critical severity with high confidentiality impact and high availability impact, but no integrity impact. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local write access to the backing file used by Data::RadixTree::Shared to trusted users only to prevent poisoning of node records. Monitor for vendor updates regarding an official patch or workaround.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-07-02T16:24:17.912Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5fc4922a4a8d5989a1c9f9
Added to database: 07/21/2026, 19:12:18 UTC
Last enriched: 07/30/2026, 08:53:27 UTC
Last updated: 09/04/2026, 10:52:10 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.