PT-2026-29223 · Zstandard+1 · Zstandard+1

Published

2026-03-31

·

Updated

2026-04-02

·

CVE-2024-14031

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sereal::Encoder versions 4.000 through 4.009 002
Description Sereal::Encoder for Perl includes a vulnerable version of the Zstandard (zstd) library. A race condition exists in the one-pass compression functions of Zstandard versions prior to 1.3.8, potentially allowing an attacker to write bytes out of bounds when using an output buffer smaller than the recommended size.
Recommendations Update Sereal::Encoder to a version that includes Zstandard 1.3.8 or later.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-14031

Affected Products

Sereal::Encoder
Zstandard