HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. 

Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Advisories

No advisories yet.

Fixes

Solution

Users should update to version 0.032 or later, where the bundled HarfBuzz library was updated to version 12.3.0.


Workaround

No workaround given by the vendor.

History

Wed, 21 Jan 2026 01:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 Jan 2026 18:45:00 +0900

Type Values Removed Values Added
First Time appeared Harfbuzz Project
Harfbuzz Project harfbuzz
Vendors & Products Harfbuzz Project
Harfbuzz Project harfbuzz

Mon, 19 Jan 2026 12:30:00 +0900

Type Values Removed Values Added
Description HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Title HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability
Weaknesses CWE-1395
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-01-20T15:25:23.530Z

Reserved: 2026-01-14T15:30:04.686Z

Link: CVE-2026-0943

cve-icon Vulnrichment

Updated: 2026-01-20T15:25:16.195Z

cve-icon NVD

Status : Received

Published: 2026-01-19T04:15:58.710

Modified: 2026-01-20T16:16:07.567

Link: CVE-2026-0943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-19T18:18:45Z

Weaknesses