CVE-2026-0943: Jv Harfbuzz::shaper
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Affected products
- Jv Harfbuzz::shaper: before 0.032 (fixed in 0.032)
Published 2026-01-19. Last modified 2026-06-17.