CVE-2026-60075: CWE-1333 Inefficient Regular Expression Complexity in SBECK Date::Manip
Date::Manip versions up to 6.99 for Perl contain an inefficient regular expression in the _parse_time function that can cause CPU exhaustion. The vulnerability arises from quadratic backtracking when parsing unanchored time substitutions in strings with long runs of whitespace. This can lead to denial of service by causing excessive CPU usage during parsing. Any untrusted input with large whitespace sequences passed to ParseDate(), Date::Manip::Date->parse(), or ->parse_time() can trigger this condition.
AI Analysis
Technical Summary
CVE-2026-60075 describes a vulnerability in Date::Manip versions through 6.99 where the _parse_time function uses an unanchored substitution with a complex regular expression that leads to quadratic backtracking. The pattern attempts to match time expressions preceded by whitespace or string start, but when given a long run of whitespace without digits, the regex engine backtracks extensively, causing CPU usage to increase quadratically with whitespace length. This results in a denial of service via CPU exhaustion when parsing untrusted input strings of unbounded length.
Potential Impact
The vulnerability allows an attacker to cause a denial of service by forcing the Date::Manip parser to consume excessive CPU resources. This occurs even if no actual time data is present, as long runs of whitespace trigger the inefficient regex backtracking. The impact is unbounded CPU consumption leading to potential service disruption or degradation in any application using affected versions of Date::Manip to parse untrusted input.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid passing untrusted or unbounded-length strings containing long whitespace runs to ParseDate(), Date::Manip::Date->parse(), or ->parse_time(). Consider input validation or limiting input size to mitigate the risk of CPU exhaustion.
CVE-2026-60075: CWE-1333 Inefficient Regular Expression Complexity in SBECK Date::Manip
Description
Date::Manip versions up to 6.99 for Perl contain an inefficient regular expression in the _parse_time function that can cause CPU exhaustion. The vulnerability arises from quadratic backtracking when parsing unanchored time substitutions in strings with long runs of whitespace. This can lead to denial of service by causing excessive CPU usage during parsing. Any untrusted input with large whitespace sequences passed to ParseDate(), Date::Manip::Date->parse(), or ->parse_time() can trigger this condition.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-60075 describes a vulnerability in Date::Manip versions through 6.99 where the _parse_time function uses an unanchored substitution with a complex regular expression that leads to quadratic backtracking. The pattern attempts to match time expressions preceded by whitespace or string start, but when given a long run of whitespace without digits, the regex engine backtracks extensively, causing CPU usage to increase quadratically with whitespace length. This results in a denial of service via CPU exhaustion when parsing untrusted input strings of unbounded length.
Potential Impact
The vulnerability allows an attacker to cause a denial of service by forcing the Date::Manip parser to consume excessive CPU resources. This occurs even if no actual time data is present, as long runs of whitespace trigger the inefficient regex backtracking. The impact is unbounded CPU consumption leading to potential service disruption or degradation in any application using affected versions of Date::Manip to parse untrusted input.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid passing untrusted or unbounded-length strings containing long whitespace runs to ParseDate(), Date::Manip::Date->parse(), or ->parse_time(). Consider input validation or limiting input size to mitigate the risk of CPU exhaustion.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-07-08T10:28:02.310Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6b5ad09c2644c7f82c544b
Added to database: 07/30/2026, 14:08:16 UTC
Last enriched: 07/30/2026, 14:24:55 UTC
Last updated: 07/30/2026, 14:54:09 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.