Security Advisories (2)
CVE-2026-60074 (2026-07-30)

Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction. Any caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed.

CVE-2026-60075 (2026-07-30)

Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes. Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date->parse() or ->parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.

NAME

Date::Manip::Lang - date manipulation routines (language initialization)

DESCRIPTION

This module is a series of routines, one per language, used to initialize the support for different languages in Date::Manip

ADDING A LANGUAGE

Adding a language is easily done. If you want to add a language, refer to the list of words and phrases given below. Translate them into the desired language and email them to me.

Note that Date::Manip does support international character sets, so if there are non-ASCII characters in the words, it's not a problem. Be sure to include an ASCII representation as well that can be used in cases where non-ASCII characters might cause problems. In many cases, alternate spellings are allowed, and there may be multiple words or phrases which fit, so please include all of them (with ASCII representations for any that include non-ASCII characters).

Please translate ALL of the following. In some cases, a phrase is given in parentheses. It is not necessary to translate the phrase. They're there to show the word in the correct context.

month names (January February ...)
abbreviations (Jan Feb ...)

day name (Monday Tuesday ... Sunday)
abbreviation (Mon Tue ... Sun)
short abbrev. (M T ... S)

number suffix (1st 2nd ... 31st)
spelled out (first second ... thirty-first

now
today
tomorrow
yesterday

last (last day of the month)

each (each Tuesday of the month)

of (first day of the week)

at (at 3:00)

on (on Tuesday)

next (next Tuesday)

last (last Tuesday)

exactly (in exactly 3 hours)

approximately (in approximately 3 hours)

business (in 4 business days)



Some times of the day are named. At the very least, there is
probably noon and midnight. Provide all named times, and the
time of day.
   noon      12:00:00
   midnight  00:00:00

The delta field names can be written or abbreviated in many differet
ways. Provide all names and abbreviations for the seven fields. For
example:
   years/year/yrs/yr/y
   months/month/mon
   weeks/week/wk/wks/w
   days/day/d
   hours/hour/hr/hrs
   minutes/minute/min/mn
   seconds/second/sec/s

What words/phrases can be used to say that a time is in the future? E.g.
   IN 3 hours
   3 hours LATER
   3 hours IN THE FUTURE
In the past?
   3 hours AGO
   3 hours PAST

Does the language have an equivalent of the English AM/PM? If so,
what are all possible values of each?

Other than a comma or period, are there any common integer/decimal
separators? For example: 1.25 can be expressed as 1.25 or 1,25
commonly. Are there any other ways?

When expressing time the hours/minutes and minutes/seconds are
typically separated by colons. Are there any other separators?
If so, what combinations of the separators are used in real life?
For example: 05h30:00.
  NOTE: there must be the same number of sephm and sepms values
        and the first sephm corresponds to the first sepms, etc.

AUTHOR

Sullivan Beck (sbeck@cpan.org)

You can always get the newest beta version of Date::Manip (which may fix problems in the current CPAN version... and may add others) from my home page:

http://www.cise.ufl.edu/~sbeck/