CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16634

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-07-24
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document. TOML::XS version 0.06 or later uses the successor tomlc17 library.

⚡ Watch CVE-2026-16634

Get an email if CVE-2026-16634 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-16634

CVE.org record

Embed the live status

CVE-2026-16634 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16634 status](https://www.csirts.com/badge/CVE-2026-16634)](https://www.csirts.com/cve/CVE-2026-16634)