CVE-2024-14031

8.1 HIGH
Published: March 31, 2026 Modified: April 13, 2026
View on NVD

Description

Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/advisories/GHSA-w77f-wv46-4vcx
Source: 9b29abf9-4ab0-4765-b253-1875cd9b441e
Not Applicable
https://metacpan.org/release/YVES/Sereal-Encoder-4.010/changes
Source: 9b29abf9-4ab0-4765-b253-1875cd9b441e
Release Notes
https://www.cve.org/CVERecord?id=CVE-2019-11922
Source: 9b29abf9-4ab0-4765-b253-1875cd9b441e
Not Applicable

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
8.1 / 10.0
EPSS (Exploit Probability)
0.1%
17th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

yves