Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys.

The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions.

Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies.

An application that looks up externally supplied strings in a tied hash will die on an invalid key.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade to Tie::Hash::Regex version 2.0.0 or later.


Workaround

For deployments that cannot be upgraded, ensure that calls to check the existence of keys, fetch values from keys or delete keys are wrapped in an eval block.

History

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
References

Sat, 22 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies. An application that looks up externally supplied strings in a tied hash will die on an invalid key.
Title Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Weaknesses CWE-248
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-22T04:12:19.600Z

Reserved: 2026-08-21T11:41:39.920Z

Link: CVE-2026-77781

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T00:16:46.710

Modified: 2026-08-22T04:18:18.383

Link: CVE-2026-77781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T03:00:12Z

Weaknesses