Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6458 articles · 192352 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-48962EXPLOITEDPATCHED
perl · io::compress

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob

Description

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

Affected Products

VendorProductVersions
perlio::compress0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmaixcert_advisory90%
ibmvioscert_advisory90%
red hatenterprise linuxcert_advisory90%

References

  • https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch(patch)
  • https://metacpan.org/release/PMQS/IO-Compress-2.220/changes(release-notes)

Related News (7 articles)

Tier B
BSI Advisories1h ago
[NEU] [hoch] IBM AIX und VIOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories53d ago
[NEU] [mittel] Red Hat Enterprise Linux (perl-IO-Compress): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes
→ No new info (linked only)
Tier B
CERT-FR68d ago
Multiples vulnérabilités dans les produits Microsoft (10 juin 2026)
→ No new info (linked only)
Tier A
Microsoft MSRC78d ago
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
→ No new info (linked only)
Tier C
VulDB82d ago
CVE-2026-48962 | PMQS IO::Compress up to 2.219 on Perl _parseOutputGlob eval injection
→ No new info (linked only)
Tier C
oss-security82d ago
CVE-2026-48962: IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
→ No new info (linked only)
CVSS 3.17.5 HIGH
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.220
CWECWE-95
PublishedMay 27, 2026
Last enriched53d agov4
Tags
CVE-2026-48962Red Hat
Trending Score80
Source articles7
Independent5
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-12087EXP
Socket versions before 2.041 for Perl have an out-of-bounds heap read
Trending: 69
NONECVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
Trending: 13
CRITICALCVE-2026-14739EXP
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
Trending: 12
NONECVE-2026-14380EXP
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Trending: 9
NONECVE-2026-8450EXP
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 27, 2026
Discovered by ZDM
May 27, 2026
Updated: severity, cvssEstimate, exploitAvailable, activelyExploited
May 27, 2026
Updated: severity, cweIds, tags
May 27, 2026
Actively Exploited
May 27, 2026
Exploit Available
May 27, 2026
Patch Available
May 27, 2026
Updated: severity, tags
Jun 25, 2026

Version History

v4
Last enriched 53d ago
v4Tier B53d ago

Updated vendor to Red Hat, product to Enterprise Linux, severity to HIGH, and added new tag for Red Hat.

severitytags
via BSI Advisories
v3Tier C82d ago

Updated severity to CRITICAL, added CWE-94, and included CVE-2026-48962 as a new tag.

severitycweIdstags
via VulDB
v2Tier C82d ago

Updated severity to HIGH, added CVSS estimate of 7.5, and marked the vulnerability as actively exploited with an exploit available.

severitycvssEstimateexploitAvailableactivelyExploited
via oss-security
v182d ago

Initial creation