CVE-2026-7111: CWE-825 Expired Pointer Dereference in HMBRAND Text::CSV_XS
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argument stack enough to trigger a reallocation, the return value is written through the stale pointer into the freed buffer, and the caller reads the original $self argument as the return value instead. Calling code that expects parsed data from getline_all receives the Text::CSV_XS object in its place, leading to logic errors or crashes. Text::CSV_XS objects used without any registered callbacks are not affected.
AI Analysis
Technical Summary
CVE-2026-7111 is a use-after-free vulnerability in Text::CSV_XS versions prior to 1.62. The issue arises when methods such as parse, print, getline, and getline_all invoke registered callbacks that extend the Perl argument stack, causing reallocation. The cached pointer to the Perl argument stack becomes stale, and the return value is written through this freed pointer, leading to the caller reading the original $self argument as the return value. This can cause type confusion or memory corruption, with calling code receiving the Text::CSV_XS object instead of parsed data. Code without registered callbacks is unaffected.
Potential Impact
Exploitation of this vulnerability can lead to high impact including memory corruption, type confusion, logic errors, and application crashes. The integrity and availability of applications using affected versions of Text::CSV_XS with registered callbacks can be compromised.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid using registered callbacks that extend the Perl argument stack with affected versions of Text::CSV_XS. Alternatively, upgrade to version 1.62 or later once confirmed fixed by the vendor.
CVE-2026-7111: CWE-825 Expired Pointer Dereference in HMBRAND Text::CSV_XS
Description
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argument stack enough to trigger a reallocation, the return value is written through the stale pointer into the freed buffer, and the caller reads the original $self argument as the return value instead. Calling code that expects parsed data from getline_all receives the Text::CSV_XS object in its place, leading to logic errors or crashes. Text::CSV_XS objects used without any registered callbacks are not affected.
CVSS v3.1
Score 8.4high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-7111 is a use-after-free vulnerability in Text::CSV_XS versions prior to 1.62. The issue arises when methods such as parse, print, getline, and getline_all invoke registered callbacks that extend the Perl argument stack, causing reallocation. The cached pointer to the Perl argument stack becomes stale, and the return value is written through this freed pointer, leading to the caller reading the original $self argument as the return value. This can cause type confusion or memory corruption, with calling code receiving the Text::CSV_XS object instead of parsed data. Code without registered callbacks is unaffected.
Potential Impact
Exploitation of this vulnerability can lead to high impact including memory corruption, type confusion, logic errors, and application crashes. The integrity and availability of applications using affected versions of Text::CSV_XS with registered callbacks can be compromised.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid using registered callbacks that extend the Perl argument stack with affected versions of Text::CSV_XS. Alternatively, upgrade to version 1.62 or later once confirmed fixed by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-04-26T15:31:25.111Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69f2370ccbff5d8610306485
Added to database: 04/29/2026, 16:51:24 UTC
Last enriched: 06/25/2026, 20:13:27 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 133
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.