CVE-2026-7040: Rrwo Text::minify::xs
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters. The minify functions mishandled some malformed UTF-8 characters, leading to heap corruption. Note that the minify_utf8 function is an alias for minify.
Affected products
- Rrwo Text::minify::xs: from 0.3.0, before 0.7.8 (fixed in 0.7.8)
Published 2026-04-27. Last modified 2026-06-17.