CVE-2024-14031
YVES Sereal::Encoder, sereal::encoder
Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
- CVSS
- 8.1
- EPSS
- 0.36% 28.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.31