CVE-2014-4330: Data Dumper Project Data Dumper
Low severity, CVSS 2.1. EPSS: 0.6% chance of exploitation in the next 30 days.
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
Affected products
- Data Dumper Project Data Dumper: up to and including 2.151
- Perl Perl: up to and including 5.20.1
Published 2014-09-30. Last modified 2026-06-17.