Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-59147— Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find

AI Predicted 4.4 Difficulty: Easy EPSS 0.42% · P34

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
EGORData::DisjointSet::Shared< 0.02affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-59147

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find
Source: CVE Program / CVE List V5
Vulnerability Description
Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. dsu_find walks and path-compresses parent[x] with x a raw file-stored index never bounded against the node count, so both the read and the compression write-back land out of bounds. A local peer that can write the backing file can leave the header valid while poisoning the parent array, so the next find or union both reads and writes through an out-of-bounds parent index, corrupting memory or crashing the process.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5
Vulnerability Title
EGOR Data::DisjointSet::Shared 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
EGOR Data::DisjointSet::Shared是EGOR个人开发者的一个用于实现不相交集合数据结构共享的Perl模块。 EGOR Data::DisjointSet::Shared 0.02之前版本存在缓冲区错误漏洞,该漏洞源于dsu_find函数中未验证的父索引导致越界读取和写入,可能造成内存损坏或进程崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
EGORData::DisjointSet::Shared 0 ~ 0.02 -

II. Public POCs for CVE-2026-59147

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59147

登录查看更多情报信息。

Other References for CVE-2026-59147 (1)

Other References for CVE-2026-59147 (1)

Same Patch Batch · EGOR · 2026-07-21 · 23 CVEs total

CVE-2026-59145Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalid
CVE-2026-65068Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backi
CVE-2026-65062Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing
CVE-2026-65065Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap bac
CVE-2026-65069Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backi
CVE-2026-65066Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backin
CVE-2026-65063Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing
CVE-2026-65067Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing fi
CVE-2026-65064Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing f
CVE-2026-65061Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing fi
CVE-2026-59143Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via
CVE-2026-59140Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unva
CVE-2026-59146Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writ
CVE-2026-59144Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via a
CVE-2026-64613Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing fi
CVE-2026-64617Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing fi
CVE-2026-64615Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing fil
CVE-2026-64614Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing fil
CVE-2026-64616Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing f
CVE-2026-59139Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unva

Showing top 20 of 23 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-59147

No comments yet


Leave a comment