CVE-2026-14895: Bakerscot String::util
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the match at each offset of a long whitespace run, producing quadratic backtracking. The fix replaces \s*$ with \s+$. Any caller that passes untrusted input to trim or rtrim can trigger CPU exhaustion with a string containing a long run of whitespace.
Affected products
- Bakerscot String::util: before 1.36 (fixed in 1.36)
Published 2026-07-07. Last modified 2026-07-08.