CVE-2026-0943

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jv:harfbuzz\:\:shaper:*:*:*:*:*:perl:*:*

History

04 Mar 2026, 14:48

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2429296 - () https://bugzilla.redhat.com/show_bug.cgi?id=2429296 - Third Party Advisory
References () https://metacpan.org/release/JV/HarfBuzz-Shaper-0.032/changes - () https://metacpan.org/release/JV/HarfBuzz-Shaper-0.032/changes - Product, Release Notes
References () https://www.cve.org/CVERecord?id=CVE-2026-22693 - () https://www.cve.org/CVERecord?id=CVE-2026-22693 - VDB Entry, Third Party Advisory
CWE CWE-476
CPE cpe:2.3:a:jv:harfbuzz\:\:shaper:*:*:*:*:*:perl:*:*
First Time Jv
Jv harfbuzz\

20 Jan 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

19 Jan 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 04:15

Updated : 2026-03-04 14:48


NVD link : CVE-2026-0943

Mitre link : CVE-2026-0943

CVE.ORG link : CVE-2026-0943


JSON object : View

Products Affected

jv

  • harfbuzz\
CWE
CWE-476

NULL Pointer Dereference