{"id":"AZL-103320","summary":"CVE-2026-82560 affecting package perl 5.38.2-516","details":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted.","modified":"2026-09-20T14:16:34.998370030Z","published":"2026-09-19T16:16:32Z","upstream":["CVE-2026-82560"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560"}],"affected":[{"package":{"name":"perl","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"5.38.2-516"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103320.json"}}],"schema_version":"1.9.0"}