---
id: CVE-2026-107373
title: >-
  ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING
  typemap may read the SV length before stringifying the argument.


  The typemap uses

      $var = std::string( SvPV_nolen($arg), SvCUR($arg) )

  However, evaluation o…
summary: >-
  ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING
  typemap may read the SV length before stringifying the argument.


  The typemap uses

      $var = std::string( SvPV_nolen($arg), SvCUR($arg) )

  However, evaluation o…
severity: none
cwe:
  - CWE-125
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T13:17:31.253'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107373'
references:
  - url: >-
      https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: >-
      https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://rt.cpan.org/Public/Bug/Display.html?id=94110'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-80490'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
tags:
  - nvd
ingestedAt: '2026-10-10T14:06:22.282Z'
---

## Overview

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.

The typemap uses

    $var = std::string( SvPV_nolen($arg), SvCUR($arg) )

However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.

When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
