CVE-2017-20230: Nwclark Storable

Critical severity, CVSS 10.0. EPSS: 0.6% chance of exploitation in the next 30 days.

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

Affected products

  • Nwclark Storable: before 3.05 (fixed in 3.05)

Published 2026-04-21. Last modified 2026-06-17.