
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0943 is a null pointer dereference vulnerability affecting the HarfBuzz::Shaper Perl module (versions before 0.032), which bundles a vulnerable version of the HarfBuzz text shaping library (8.4.0 or earlier) as hb_src.tar.gz in its source tarball. The bundled HarfBuzz library is independently tracked as CVE-2026-22693. The vulnerability was assigned by CPANSec and published on January 19, 2026, with initial analysis completed by NIST on March 4, 2026. It carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP (Red Hat Advisory, Red Hat Bugzilla).
The root cause is a NULL Pointer Dereference (CWE-476) in the bundled HarfBuzz C library included within the HarfBuzz::Shaper Perl CPAN distribution. Because the vulnerable library is statically bundled rather than dynamically linked, systems using the Perl module are exposed even if a patched system-level HarfBuzz library is installed. The attack vector is network-accessible (AV:N), requires no authentication or user interaction, and has low attack complexity, meaning a remote attacker could trigger the dereference by supplying crafted input to any application that processes text through this module. The underlying flaw is detailed in the parent CVE-2026-22693 (Red Hat Bugzilla, CVE Record).
Successful exploitation results in a denial of service (DoS) through application crash, as the null pointer dereference causes the affected process to terminate abnormally. There is no impact on confidentiality or integrity — only availability is affected. Any Perl application that uses HarfBuzz::Shaper versions before 0.032 to process untrusted text input (e.g., web services performing font shaping or PDF/document rendering) could be crashed remotely by a malicious actor supplying crafted input (Red Hat Advisory).
The primary remediation is to upgrade the HarfBuzz::Shaper Perl module to version 0.032 or later, which bundles a patched version of HarfBuzz. For Fedora users, the fixed packages perl-HarfBuzz-Shaper-0.033-2.fc43 (Fedora 43) and perl-HarfBuzz-Shaper-0.033-1.fc42 (Fedora 42) have been pushed to the stable repositories and can be applied via sudo dnf upgrade. No configuration-based workaround is available; upgrading the CPAN module is the only effective fix (Red Hat Bugzilla, MetaCPAN Release Notes).
The vulnerability received routine coverage from automated vulnerability tracking services and social media bots (e.g., Bluesky, Mastodon). No notable researcher commentary or significant media coverage beyond standard CVE aggregation was identified. Red Hat's Product Security team triaged the issue at low/medium severity, consistent with its limited scope as a DoS-only, dependency-bundling issue (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."