Sploitus

CVE-2024-14030

No indexed exploits for CVE-2024-14030 yet

Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Decoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

Affected products
Sereal::Decoder, Zstandard
Yves Sereal\:\:decoder
< 4.010
CVSS 3.1
8.1 HIGH
EPSS
0.4% (28th percentile)
Weakness
CWE-787, CWE-1395
NVD status
Analyzed
Published
2026-03-31

Fix

Upgrade to Sereal::Decoder version 4.010 or later.

CVE-2024-14030 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-14030 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-14030 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.