Description
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. 

Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Published: 2026-01-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Harfbuzz::Shaper versions before 0.032 for Perl embed the HarfBuzz 8.4.0 or earlier source package, which is affected by a null pointer dereference vulnerability (CWE-476). The flaw can cause a segmentation fault when the library processes certain input, leading to a crash of the Perl process that ingests the module. The impact is primarily a denial of service, as the crash can terminate user‑processes or web services that rely on the module. No direct remote code execution path is described in the CVE data. The attack vector is inferred to be via legitimate use of the vulnerable Perl module, potentially triggered by crafted text rendering requests.

Affected Systems

The vulnerability affects the JV Harfbuzz::Shaper Perl module for versions prior to 0.032. Vendors include JV, and the product is distributed via CPAN as Harfbuzz::Shaper. Systems running any of the bundled HarfBuzz 8.4.0 or earlier libraries inside the module are impacted; this includes all installations where the Perl module is imported or executed. Version information from the CNA indicates that upgrades to 0.032 or later replace the bundled library with HarfBuzz 12.3.0, which removes the fault.

Risk and Exploitability

The CVSS score of 7.5 reflects a high severity impact. The EPSS score of less than 1 percent indicates a very low likelihood of exploitation in the wild at this time, and the vulnerability is not currently listed in CISA’s KEV catalog. The primary exploitation pathway is server or application crash when the module processes a user‑supplied input that triggers the null dereference. Because exploitation requires the module to be executed in the attacker’s context, the risk to systems that simply keep the module installed but do not load it is lower. Nonetheless, the high severity rating recommends remediation.

Generated by OpenCVE AI on April 18, 2026 at 15:56 UTC.

Remediation

Vendor Solution

Users should update to version 0.032 or later, where the bundled HarfBuzz library was updated to version 12.3.0.


OpenCVE Recommended Actions

  • Upgrade the Perl module to version 0.032 or later, which replaces the bundled HarfBuzz library with a fixed version.
  • Remove any remaining hb_src.tar.gz archives from the Perl include path to ensure the module does not reference the old vulnerable library.
  • Verify that the application operates correctly after the update by performing text rendering tests and monitoring for segmentation faults or crashes.

Generated by OpenCVE AI on April 18, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 04 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Jv
Jv harfbuzz\
Weaknesses CWE-476
CPEs cpe:2.3:a:jv:harfbuzz\:\:shaper:*:*:*:*:*:perl:*:*
Vendors & Products Jv
Jv harfbuzz\

Tue, 20 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Harfbuzz Project
Harfbuzz Project harfbuzz
Vendors & Products Harfbuzz Project
Harfbuzz Project harfbuzz

Mon, 19 Jan 2026 03:30:00 +0000

Type Values Removed Values Added
Description HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Title HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability
Weaknesses CWE-1395
References

Subscriptions

Harfbuzz Project Harfbuzz
Jv Harfbuzz\
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-01-20T15:25:23.530Z

Reserved: 2026-01-14T15:30:04.686Z

Link: CVE-2026-0943

cve-icon Vulnrichment

Updated: 2026-01-20T15:25:16.195Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-19T04:15:58.710

Modified: 2026-03-04T14:48:22.457

Link: CVE-2026-0943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:00:04Z

Weaknesses