CVE Explorer
CVE-2026-41565
CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers.
The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"CryptX","product":"CryptX","programFiles":["inc/CryptX_AuthEnc_GCM.xs.inc","inc/CryptX_AuthEnc_CCM.xs.inc","inc/CryptX_AuthEnc_ChaCha20Poly1305.xs.inc","inc/CryptX_AuthEnc_EAX.xs.inc"],"programRoutines":[{"name":"gcm_decrypt_verify"},{"name":"ccm_decrypt_verify"},{"name":"chacha20poly1305_decrypt_verify"},{"name":"eax_decrypt_verify"}],"repo":"https://github.com/DCIT/perl-CryptX","vendor":"MIK","versions":[{"lessThan":"0.088_001","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d041b4788ab202fa6bee2e0f58162023c8b516af85aee14cf48cbe6bff746e5e · sha256:c618594bc7a105fa… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d041b4788ab202fa6bee2e0f58162023c8b516af85aee14cf48cbe6bff746e5e · sha256:c618594bc7a105fa… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121 Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d041b4788ab202fa6bee2e0f58162023c8b516af85aee14cf48cbe6bff746e5e · sha256:c618594bc7a105fa… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/05/28/10"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d041b4788ab202fa6bee2e0f58162023c8b516af85aee14cf48cbe6bff746e5e · sha256:c618594bc7a105fa… · /containers/adp/0/references/0
{"tags":["patch"],"url":"https://github.com/DCIT/perl-CryptX/commit/57e69e541b0718ca8724c2f61514322a2d859bc1.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d041b4788ab202fa6bee2e0f58162023c8b516af85aee14cf48cbe6bff746e5e · sha256:c618594bc7a105fa… · /containers/cna/references/0
{"tags":["patch"],"url":"https://github.com/DCIT/perl-CryptX/commit/7e56347d420aaf43b2ee1586f4a230492ccf1642.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d041b4788ab202fa6bee2e0f58162023c8b516af85aee14cf48cbe6bff746e5e · sha256:c618594bc7a105fa… · /containers/cna/references/1
{"tags":["release-notes"],"url":"https://metacpan.org/release/MIK/CryptX-0.088_001"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d041b4788ab202fa6bee2e0f58162023c8b516af85aee14cf48cbe6bff746e5e · sha256:c618594bc7a105fa… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.