Security Advisories (4)
CVE-2026-13221 (2026-07-13)

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.

CVE-2026-4176 (2026-03-29)

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

CVE-2026-57432 (2026-07-13)

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.

CVE-2026-8376 (2026-05-25)

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.

NAME

TAP::Parser::Result::Test - Test result token.

VERSION

Version 3.50

DESCRIPTION

This is a subclass of TAP::Parser::Result. A token of this class will be returned if a test line is encountered.

1..1
ok 1 - woo hooo!

OVERRIDDEN METHODS

This class is the workhorse of the TAP::Parser system. Most TAP lines will be test lines and if $result->is_test, then you have a bunch of methods at your disposal.

Instance Methods

ok

my $ok = $result->ok;

Returns the literal text of the ok or not ok status.

number

my $test_number = $result->number;

Returns the number of the test, even if the original TAP output did not supply that number.

description

my $description = $result->description;

Returns the description of the test, if any. This is the portion after the test number but before the directive.

directive

my $directive = $result->directive;

Returns either TODO or SKIP if either directive was present for a test line.

explanation

my $explanation = $result->explanation;

If a test had either a TODO or SKIP directive, this method will return the accompanying explanation, if present.

not ok 17 - 'Pigs can fly' # TODO not enough acid

For the above line, the explanation is not enough acid.

is_ok

if ( $result->is_ok ) { ... }

Returns a boolean value indicating whether or not the test passed. Remember that for TODO tests, the test always passes.

If the test is unplanned, this method will always return false. See is_unplanned.

is_actual_ok

if ( $result->is_actual_ok ) { ... }

Returns a boolean value indicating whether or not the test passed, regardless of its TODO status.

actual_passed

Deprecated. Please use is_actual_ok instead.

todo_passed

if ( $test->todo_passed ) {
   # test unexpectedly succeeded
}

If this is a TODO test and an 'ok' line, this method returns true. Otherwise, it will always return false (regardless of passing status on non-todo tests).

This is used to track which tests unexpectedly succeeded.

todo_failed

# deprecated in favor of 'todo_passed'.  This method was horribly misnamed.

This was a badly misnamed method. It indicates which TODO tests unexpectedly succeeded. Will now issue a warning and call todo_passed.

has_skip

if ( $result->has_skip ) { ... }

Returns a boolean value indicating whether or not this test has a SKIP directive.

has_todo

if ( $result->has_todo ) { ... }

Returns a boolean value indicating whether or not this test has a TODO directive.

as_string

print $result->as_string;

This method prints the test as a string. It will probably be similar, but not necessarily identical, to the original test line. Directives are capitalized, some whitespace may be trimmed and a test number will be added if it was not present in the original line. If you need the original text of the test line, use the raw method.

is_unplanned

if ( $test->is_unplanned ) { ... }
$test->is_unplanned(1);

If a test number is greater than the number of planned tests, this method will return true. Unplanned tests will always return false for is_ok, regardless of whether or not the test has_todo.

Note that if tests have a trailing plan, it is not possible to set this property for unplanned tests as we do not know it's unplanned until the plan is reached:

print <<'END';
ok 1
ok 2
1..1
END