CVE-2026-19487
Last modified
CVE-2026-19487 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds. Example: "ABCDE" =~ m/ABCF|BCDE|C/; # matches C at offset 2, not BCDE "ABCDE" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | >= 5.9.4, < 5.41.9 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-19487?
How severe is CVE-2026-19487?
How do I fix CVE-2026-19487?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19479Adobe Experience Manager is affected by a DOM-based Cross-Si…5.4
- CVE-2026-1948The NEX-Forms – Ultimate Forms Plugin for WordPress plugin f…4.3
- CVE-2026-19481@fastify/busboy is a multipart form-data parser. In versions…7.5
- CVE-2026-19483IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 throu…5.5
- CVE-2026-19484@fastify/busboy is a multipart form-data parser. In versions…7.5
- CVE-2026-19485A Predictable Resource Name vulnerability in BigQuery Import…9.3
- CVE-2026-19489Vulnerability in NetScaler ADC and NetScaler Gateway. This …8.8
- CVE-2026-1949Delta Electronics AS320T has incorrect calculation of the bu…9.8
- CVE-2026-19490Vulnerability in NetScaler ADC and NetScaler Gateway. This …9.3
- CVE-2026-1950Delta Electronics AS320T has No checking of the length of t…9.8
- CVE-2026-19500The Entries component in Brainstorm Force SureForms version,…7.5
- CVE-2026-19501CSV export functionality in Brainstorm Force SureForms versi…8.8
Are you affected by CVE-2026-19487?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
