CVE-2026-80490 affects Algorithm::AhoCorasick::XS versions through 0.04
A notice published on September 30, 2026 identifies a flaw in Algorithm::AhoCorasick::XS for Perl: through version 0.04, the code reads a string's length before converting it. The source is an automated translation of content from the oss-sec feed.
A security notice identifies CVE-2026-80490 in the Perl distribution Algorithm-AhoCorasick-XS, in versions through 0.04. The description says the flaw occurs because the string length is read before conversion; the supplied excerpt gives no details about impact or a fix.
The content was published on September 30, 2026, and is an automated translation of a post from the oss-sec feed, attributed to Robert Rothenberg. The translation and available excerpt are not enough to determine a fixed version or the flaw's concrete effects.
To assess exposure, check your application's dependency inventory for the distribution and an affected version. Consult the original notice in the oss-sec feed and the distribution's records to confirm the description and look for updates; do not assume a particular version fixes the issue without verifying that information.
If you use AI to summarize the notice or support analysis, share only the material needed and remove internal data such as customer names, credentials, and system details. Validate conclusions against the original notice and the team responsible for the dependency.