CVE-2026-0943

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jv:harfbuzz\:\:shaper:*:*:*:*:*:perl:*:*

History

17 Jun 2026, 10:11

Type Values Removed Values Added
Summary
  • (es) Versiones de HarfBuzz::Shaper anteriores a la 0.032 para Perl contienen una librería incluida con una vulnerabilidad de desreferencia de puntero nulo. Las versiones anteriores a la 0.032 contienen HarfBuzz 8.4.0 o anterior incluido como hb_src.tar.gz en el tarball de origen, el cual está afectado por CVE-2026-22693.
References () https://www.cve.org/CVERecord?id=CVE-2026-22693 - VDB Entry, Third Party Advisory () https://www.cve.org/CVERecord?id=CVE-2026-22693 - Third Party Advisory, VDB Entry

04 Mar 2026, 14:48

Type Values Removed Values Added
CWE CWE-476
CPE cpe:2.3:a:jv:harfbuzz\:\:shaper:*:*:*:*:*:perl:*:*
First Time Jv
Jv harfbuzz\
References () https://bugzilla.redhat.com/show_bug.cgi?id=2429296 - () https://bugzilla.redhat.com/show_bug.cgi?id=2429296 - Third Party Advisory
References () https://metacpan.org/release/JV/HarfBuzz-Shaper-0.032/changes - () https://metacpan.org/release/JV/HarfBuzz-Shaper-0.032/changes - Product, Release Notes
References () https://www.cve.org/CVERecord?id=CVE-2026-22693 - () https://www.cve.org/CVERecord?id=CVE-2026-22693 - VDB Entry, Third Party Advisory

20 Jan 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

19 Jan 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 04:15

Updated : 2026-06-17 10:11


NVD link : CVE-2026-0943

Mitre link : CVE-2026-0943

CVE.ORG link : CVE-2026-0943


JSON object : View

Products Affected

jv

  • harfbuzz\
CWE
CWE-476

NULL Pointer Dereference