Description
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service.

The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the match at each offset of a long whitespace run, producing quadratic backtracking. The fix replaces \s*$ with \s+$.

Any caller that passes untrusted input to trim or rtrim can trigger CPU exhaustion with a string containing a long run of whitespace.
Published: 2026-07-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

String::Util versions before 1.36 use a regular‑expression pattern that matches trailing whitespace greedily, causing the Perl regex engine to backtrack quadratically when processing long runs of whitespace. When an attacker supplies such input to the trim or rtrim functions, the engine can exhaust CPU resources, resulting in a denial of service. This vulnerability is classified as CWE‑1333 and can affect any application that uses the module and passes untrusted data to trim or rtrim.

Affected Systems

Vendor BAKERSCOT produces the module String::Util. Any Perl environment that imports String::Util with a version lower than 1.36 is affected. Versions 1.36 and later contain the fix and are safe. No other vendors or products are listed by the CNA for this issue.

Risk and Exploitability

The CVSS score of 7.5 indicates a high threat level for denial of service. The EPSS score of < 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not present in the CISA KEV catalog. Attackers likely need to provide a long string of whitespace to the vulnerable functions; such input could originate from web forms, API payloads, or any interface that accepts arbitrary user data before trimming. Because the denial of service manifests as CPU exhaustion, an attacker can disrupt application availability once the vulnerable code processes the crafted input.

Generated by OpenCVE AI on July 29, 2026 at 15:02 UTC.

Remediation

Vendor Solution

Upgrade to version 1.36 or later.


Vendor Workaround

For deployments that cannot upgrade, enforce a maximum length on strings before passing them to the trim and rtrim functions. Note that the HTML form field maxlength attribute is only enforced client-side.


OpenCVE Recommended Actions

  • Upgrade String::Util to version 1.36 or newer.
  • For deployments that cannot upgrade, limit the length of strings before calling trim or rtrim.
  • Review application code that passes user‑supplied data to trim or rtrim and modify it to use a non‑backtracking pattern or omit trimming for long inputs.
  • Implement resource monitoring to detect sudden CPU spikes that may indicate a denial‑of‑service attack.

Generated by OpenCVE AI on July 29, 2026 at 15:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Bakerscot
Bakerscot string::util
Vendors & Products Bakerscot
Bakerscot string::util

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the match at each offset of a long whitespace run, producing quadratic backtracking. The fix replaces \s*$ with \s+$. Any caller that passes untrusted input to trim or rtrim can trigger CPU exhaustion with a string containing a long run of whitespace.
Title String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
Weaknesses CWE-1333
References

Subscriptions

Bakerscot String::util
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-08T14:05:18.813Z

Reserved: 2026-07-06T18:31:10.251Z

Link: CVE-2026-14895

cve-icon Vulnrichment

Updated: 2026-07-08T00:28:33.750Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T15:15:03Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity