Security Advisories (2)
CVE-2026-60074 (2026-07-30)

Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction. Any caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed.

CVE-2026-60075 (2026-07-30)

Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes. Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date->parse() or ->parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.

NAME

Date::Manip::DM5abbrevs - A list of all timezone abbreviations

SYNPOSIS

This module is not intended to be used directly. Date::Manip 5.xx will load it as needed.

This module contains all of the time zone abbreviations from Date::Manip 6.xx copied backwards to 5.xx to provide slightly better support for time zones.

Note that this is only a bandaid fix, and does not add proper time zone handling to version 5.xx .

TIMEZONES

The following timezones are defined:

A      -0100
ACDT   +1030
ACST   +0930
ADDT   -0200
ADT    -0300
AEDT   +1100
AEST   +1000
AHDT   -0900
AHST   -1000
AKDT   -0800
AKST   -0900
APT    -0900
AST    -0400
AT     -0200
AWDT   +0900
AWST   +0800
AWT    -0300
B      -0200
BDST   +0200
BDT    -1000
BST    +0100
BT     +0300
C      -0300
CADT   +1030
CAST   +0300
CAT    +0200
CDT    -0500
CEMT   +0300
CEST   +0200
CET    +0100
CHST   +1000
CLDT   -0300
CMT    +0155
CPT    -0500
CST    -0600
CWT    -0500
D      -0400
E      -0500
EADT   +1100
EAT    +0300
EDT    -0400
EEST   +0300
EET    +0200
EETDST +0300
EETEDT +0300
EPT    -0400
EST    -0500
EWT    -0400
F      -0600
FST    +0200
FWT    +0100
G      -0700
GB     +0100
GDT    +1100
GMT    +0000
GMT+1  +0100
GMT+10 +1000
GMT+11 +1100
GMT+12 +1200
GMT+2  +0200
GMT+3  +0300
GMT+4  +0400
GMT+5  +0500
GMT+6  +0600
GMT+7  +0700
GMT+8  +0800
GMT+9  +0900
GMT-1  -0100
GMT-10 -1000
GMT-11 -1100
GMT-12 -1200
GMT-13 -1300
GMT-14 -1400
GMT-2  -0200
GMT-3  -0300
GMT-4  -0400
GMT-5  -0500
GMT-6  -0600
GMT-7  -0700
GMT-8  -0800
GMT-9  -0900
GST    +1000
H      -0800
HDT    -0900
HKST   +0900
HKT    +0800
HKWT   +0830
HPT    -0930
HST    -1000
HWT    -0930
I      -0900
IDDT   +0400
IDLE   +1200
IDLW   -1200
IDT    +0300
IST    +0530
IT     +0330
JDT    +1000
JST    +0900
K      -1000
KDT    +1000
KST    +0900
L      -1100
M      -1200
MDT    -0600
MESZ   +0200
METDST +0200
MEWT   +0100
MEZ    +0100
MMT    +0454
MPT    -0600
MSD    +0400
MSK    +0300
MST    -0700
MWT    -0600
N      +0100
NDDT   -0130
NDT    -0230
NPT    -1000
NST    -0330
NT     -1100
NWT    -1000
NZDT   +1300
NZMT   +1130
NZST   +1200
NZT    +1200
O      +0200
P      +0300
PDT    -0700
PKST   +0600
PKT    +0500
PPMT   -0449
PPT    -0700
PST    -0800
PWT    -0700
Q      +0400
QMT    -0514
R      +0500
ROK    +0900
S      +0600
SAST   +0200
SAT    -0400
SDMT   -0440
SMT    +0216
SST    -1100
SWT    +0100
T      +0700
TMT    +0139
U      +0800
UT     +0000
UTC    +0000
V      +0900
W      +1000
WAST   +0200
WAT    +0100
WEMT   +0200
WEST   +0100
WET    +0000
WIB    +0700
WIT    +0900
WITA   +0800
WMT    +0124
X      +1100
Y      +1200
YDDT   -0700
YDT    -0800
YPT    -0800
YST    -0900
YWT    -0800
Z      +0000
ZP4    +0400
ZP5    +0500
ZP6    +0600

LICENSE

This script is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

AUTHOR

Sullivan Beck (sbeck@cpan.org)