CVE-2014-4330: Data Dumper Project Data Dumper

Low severity, CVSS 2.1. EPSS: 0.6% chance of exploitation in the next 30 days.

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

Affected products

Published 2014-09-30. Last modified 2026-06-17.