Description
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys.

The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions.

Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies.

An application that looks up externally supplied strings in a tied hash will die on an invalid key.
Published: 2026-08-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Application Crash
Action: Immediate Patch
AI Analysis

Impact

Tie::Hash::Regex versions prior to 2.0.0 will raise an exception when a lookup key cannot be parsed as a valid regular expression. This flaw is a CWE‑248 exception handling weakness. When an application performs FETCH, EXISTS, or DELETE on a tied hash with an externally supplied key that is not a valid regex pattern, the module compiles the key with a bare qr// without any exception guard, causing the Perl interpreter to die. The resulting crash truncates the application’s execution and can result in a denial of service.

Affected Systems

This issue affects any installation that uses the Tie::Hash::Regex Perl module of version 1.x or earlier. The module is distributed by the DAVECROSS project and is used in Perl environments where arbitrary strings are queried against a tied hash.

Risk and Exploitability

The vulnerability is exploitable if an attacker can provide or influence the key used in a hash lookup. The CVSS score of 7.5 indicates a high severity; the EPSS score of < 1% shows a low but nonzero probability of exploitation in the wild. The module falls back to compiling the input key as an unguarded regex match when it is not already stored in the hash, causing the Perl interpreter to die when the key contains an invalid regex pattern such as an unmatched bracket. If an application receives externally supplied strings and uses them directly as hash keys, the resulting crash truncates the application’s execution and can lead to a denial of service. Though the exploitation vector requires influencing a lookup key, such as through user input, the impact is significant for systems that rely on Tie::Hash::Regex for dynamic hash lookups.

Generated by OpenCVE AI on August 28, 2026 at 19:15 UTC.

Remediation

Vendor Solution

Upgrade to Tie::Hash::Regex version 2.0.0 or later.


Vendor Workaround

For deployments that cannot be upgraded, ensure that calls to check the existence of keys, fetch values from keys or delete keys are wrapped in an eval block.


OpenCVE Recommended Actions

  • Upgrade Tie::Hash::Regex to version 2.0.0 or later.
  • If an upgrade is not possible, wrap any call to FETCH, EXISTS or DELETE that uses externally supplied keys in an eval block to catch exceptions.
  • Validate or sanitize lookup keys before using them to ensure they are valid regular expressions.

Generated by OpenCVE AI on August 28, 2026 at 19:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Davorg-cpan
Davorg-cpan tie Hash Regex
Vendors & Products Davorg-cpan
Davorg-cpan tie Hash Regex

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
References

Sat, 22 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies. An application that looks up externally supplied strings in a tied hash will die on an invalid key.
Title Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Weaknesses CWE-248
References

Subscriptions

Davorg-cpan Tie Hash Regex
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-27T19:12:59.227Z

Reserved: 2026-08-21T11:41:39.920Z

Link: CVE-2026-77781

cve-icon Vulnrichment

Updated: 2026-08-22T04:12:19.600Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T00:16:46.710

Modified: 2026-08-27T20:18:39.550

Link: CVE-2026-77781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:30:16Z

Weaknesses