CVE-2026-19487

EUVD-2026-58110
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.

Example:

  "ABCDE" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE
  "ABCDE" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed

An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 33.63%
Debian logo
Debian Releases
Debian Product
Codename
perl
bookworm
vulnerable
bookworm (security)
vulnerable
forky
5.42.3-1
fixed
sid
5.42.3-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
perl
bionic
Fixed 5.26.1-6ubuntu0.7+esm4
released
focal
Fixed 5.30.0-9ubuntu0.5+esm4
released
jammy
Fixed 5.34.0-3ubuntu1.9
released
noble
Fixed 5.38.2-3.2ubuntu0.6
released
resolute
Fixed 5.40.1-7ubuntu0.2
released
trusty
Fixed 5.18.2-2ubuntu1.7+esm9
released
xenial
Fixed 5.22.1-9ubuntu0.9+esm4
released
Azure Linux logo
Azure Linux Releases
Azure Package
Release
perl
Azure Linux 3.0
0:5.38.2-516.azl3
fixed