CVE-2023-31484: Cpanpm Project Cpanpm
High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
Affected products
- Cpanpm Project Cpanpm: before 2.35 (fixed in 2.35)
- Perl Perl: before 5.38.0 (fixed in 5.38.0)
Published 2023-04-29. Last modified 2026-06-17.