CVE-2026-59147: CWE-787 Out-of-bounds Write in EGOR Data::DisjointSet::Shared
Data::DisjointSet::Shared versions before 0.02 for Perl contain an out-of-bounds read and write vulnerability in the dsu_find function. This occurs because the parent index used in dsu_find is not validated against the node count, allowing memory corruption or process crashes. The vulnerability arises despite a header validation step that does not check array contents. A local attacker able to modify the backing file can exploit this to cause memory corruption or crashes.
AI Analysis
Technical Summary
CVE-2026-59147 is an out-of-bounds read and write vulnerability in the Perl module Data::DisjointSet::Shared versions prior to 0.02. The vulnerability is due to the dsu_find function using an unvalidated parent index derived from a file-stored array, which is not bounded by the node count. Although the attach-time validator dsu_validate_header checks header scalars and region layout against file size, it does not validate the array contents. This allows a local attacker who can write to the backing file to craft a valid header but poison the parent array, leading to out-of-bounds memory access during subsequent find or union operations. The CVSS 3.1 score is 9.8, indicating critical severity with network attack vector, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with local write access to the backing file to cause out-of-bounds memory reads and writes, potentially leading to memory corruption, process crashes, and possibly arbitrary code execution. The vulnerability affects confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local write access to the backing file used by Data::DisjointSet::Shared to trusted users only to prevent poisoning of the parent array. Monitor for updates from the EGOR project regarding an official fix.
CVE-2026-59147: CWE-787 Out-of-bounds Write in EGOR Data::DisjointSet::Shared
Description
Data::DisjointSet::Shared versions before 0.02 for Perl contain an out-of-bounds read and write vulnerability in the dsu_find function. This occurs because the parent index used in dsu_find is not validated against the node count, allowing memory corruption or process crashes. The vulnerability arises despite a header validation step that does not check array contents. A local attacker able to modify the backing file can exploit this to cause memory corruption or crashes.
CVSS v3.1
Score 9.8critical
Affected software
pkg:github/Data-DisjointSet-SharedRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59147 is an out-of-bounds read and write vulnerability in the Perl module Data::DisjointSet::Shared versions prior to 0.02. The vulnerability is due to the dsu_find function using an unvalidated parent index derived from a file-stored array, which is not bounded by the node count. Although the attach-time validator dsu_validate_header checks header scalars and region layout against file size, it does not validate the array contents. This allows a local attacker who can write to the backing file to craft a valid header but poison the parent array, leading to out-of-bounds memory access during subsequent find or union operations. The CVSS 3.1 score is 9.8, indicating critical severity with network attack vector, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with local write access to the backing file to cause out-of-bounds memory reads and writes, potentially leading to memory corruption, process crashes, and possibly arbitrary code execution. The vulnerability affects confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local write access to the backing file used by Data::DisjointSet::Shared to trusted users only to prevent poisoning of the parent array. Monitor for updates from the EGOR project regarding an official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-07-02T16:24:17.913Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5fcbb52a4a8d5989ac6cd8
Added to database: 07/21/2026, 19:42:45 UTC
Last enriched: 07/30/2026, 05:30:34 UTC
Last updated: 09/04/2026, 10:52:10 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.