CVE-2026-16634
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/07/2026
Last modified:
27/07/2026
Description
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.<br />
<br />
The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker.<br />
<br />
Any caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document.<br />
<br />
TOML::XS version 0.06 or later uses the successor tomlc17 library.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/cktan/tomlc17
- https://github.com/cktan/tomlc99/issues/97
- https://metacpan.org/release/FELIPE/TOML-XS-0.06/changes
- https://raw.githubusercontent.com/cktan/tomlc99/29076dfd095bbbbd50a3c1b2760d29f4b83e74ac/README.md
- https://toml.io/en/v1.0.0
- http://www.openwall.com/lists/oss-security/2026/07/24/4
- https://github.com/cktan/tomlc99/issues/97



