CVE-2023-31484: Cpanpm Project Cpanpm

High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

Affected products

  • Cpanpm Project Cpanpm: before 2.35 (fixed in 2.35)
  • Perl Perl: before 5.38.0 (fixed in 5.38.0)

Published 2023-04-29. Last modified 2026-06-17.