HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.
Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Metrics
Affected Vendors & Products
References
History
Tue, 20 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Harfbuzz Project
Harfbuzz Project harfbuzz |
|
| Vendors & Products |
Harfbuzz Project
Harfbuzz Project harfbuzz |
Mon, 19 Jan 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693. | |
| Title | HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability | |
| Weaknesses | CWE-1395 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published: 2026-01-19T02:46:52.012Z
Updated: 2026-01-20T15:25:23.530Z
Reserved: 2026-01-14T15:30:04.686Z
Link: CVE-2026-0943
Updated: 2026-01-20T15:25:16.195Z
Status : Received
Published: 2026-01-19T04:15:58.710
Modified: 2026-01-20T16:16:07.567
Link: CVE-2026-0943
No data.