The minify functions mishandled some malformed UTF-8 characters, leading to heap corruption.
Note that the minify_utf8 function is an alias for minnify.
Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to v0.7.8 or later.
Workaround
Validate that all strings passed to the minify and minify_utf8 functions.
Mon, 27 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 27 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters. The minify functions mishandled some malformed UTF-8 characters, leading to heap corruption. Note that the minify_utf8 function is an alias for minnify. | |
| Title | Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters | |
| Weaknesses | CWE-122 CWE-176 |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-04-27T14:20:30.162Z
Reserved: 2026-04-25T15:53:43.870Z
Link: CVE-2026-7040
Updated: 2026-04-27T14:19:56.434Z
Status : Received
Published: 2026-04-27T13:16:02.710
Modified: 2026-04-27T15:16:21.070
Link: CVE-2026-7040
No data.
OpenCVE Enrichment
No data.