Skip to content
Rota Nacional

Cyber ·

CVE-2026-85644 affects XS-Parse-Keyword in Perl

A notice published on September 28, 2026 reports that XS::Parse::Infix may treat a number as an array reference. The issue is associated with XS-Parse-Keyword versions 0.40 to 0.49; the notice provided is truncated.

A security notice reproduced in an automatic translation on the oss-sec feed reports CVE-2026-85644, concerning XS::Parse::Infix for Perl. According to the material, the flaw causes a number to be treated as an array reference and affects versions 0.40 to 0.49 of the XS-Parse-Keyword distribution. The item is dated September 28, 2026 and credits its publication to Robert Rothenberg.

The available text is truncated, so it does not detail exploitation conditions, further impact, or fixes. To confirm the scope and look for updates, consult the original notice in the oss-sec archive and the distribution page on MetaCPAN; compare the installed version with the affected range and check for maintainer advisories. Do not infer a fix from the reproduced excerpt alone.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free