Security Advisories (1)
CVE-2026-0943 (2026-01-19)

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

NAME

HarfBuzz::Shaper - Use HarfBuzz for text shaping

SYNOPSIS

use HarfBuzz::Shaper;
blah blah blah

DESCRIPTION

Stub documentation for HarfBuzz::Shaper, created by h2xs. It looks like the author of the extension was negligent enough to leave the stub unedited.

Blah blah blah.

METHODS

new

SEE ALSO

AUTHOR

Johan Vromans, <jv@cpan.org<gt>

COPYRIGHT AND LICENSE

Copyright (C) 2020 by Johan Vromans

This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself, either Perl version 5.28.2 or, at your option, any later version of Perl 5 you may have available.