Security Advisories (2)
CVE-2026-60074 (2026-07-30)

Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction. Any caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed.

CVE-2026-60075 (2026-07-30)

Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes. Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date->parse() or ->parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.

NAME

Date::Manip::DM5abbrevs - A list of all timezone abbreviations

SYNPOSIS

This module is not intended to be used directly. Date::Manip 5.xx will load it as needed.

This module contains all of the time zone abbreviations from Date::Manip 6.xx copied backwards to 5.xx to provide slightly better support for time zones.

Note that this is only a bandaid fix, and does not add proper time zone handling to version 5.xx .

TIMEZONES

The following timezones are defined:

A      -0100
ACDT   +1030
ACST   +0930
ACT    -0500
ACWDT  +0945
ACWST  +0845
ADDT   -0200
ADT    -0300
AEDT   +1100
AEST   +1000
AFT    +0430
AHDT   -0900
AHST   -1000
AKDT   -0800
AKST   -0900
AMST   -0300
AMT    -0400
ANT    -0430
APT    -0300
ARST   -0200
ART    -0300
AST    -0400
AT     -0200
AWDT   +0900
AWST   +0800
AWT    -0300
AZOMT  +0000
AZOST  +0000
AZOT   -0100
B      -0200
BDST   +0700
BDT    +0600
BEAT   +0230
BEAUT  +0245
BNT    +0800
BORT   +0800
BORTST +0820
BOT    -0400
BRST   -0200
BRT    -0300
BST    +0100
BT     +0300
BTT    +0600
BURT   +0630
C      -0300
CADT   +1030
CANT   -0100
CAPT   -0900
CAST   +0300
CAT    +0200
CAWT   -0900
CCT    +0630
CDDT   -0400
CDT    -0500
CEMT   +0300
CEST   +0200
CET    +0100
CGST   -0100
CGT    -0200
CHADT  +1345
CHAST  +1245
CHDT   -0530
CHOST  +0900
CHOT   +0800
CHST   +1000
CHUT   +1000
CKHST  -0930
CKT    -1000
CLDT   -0300
CLST   -0300
CLT    -0400
CMT    +0155
COST   -0400
COT    -0500
CPT    -0500
CST    -0600
CUT    +0220
CVST   -0100
CVT    -0100
CWT    -0500
CXT    +0700
D      -0400
DACT   +0600
E      -0500
EADT   +1100
EASST  -0500
EAST   -0600
EAT    +0300
ECT    -0500
EDDT   -0300
EDT    -0400
EEST   +0300
EET    +0200
EETDST +0300
EETEDT +0300
EGST   +0000
EGT    -0100
EHDT   -0430
EPT    -0400
EST    -0500
EWT    -0400
F      -0600
FJST   +1300
FJT    +1200
FKST   -0300
FKT    -0400
FNST   -0100
FNT    -0200
FST    +0200
FWT    +0100
G      -0700
GALT   -0600
GAMT   -0900
GB     +0100
GBGT   -0345
GFT    -0300
GHST   +0020
GILT   +1200
GMT    +0000
GMT+1  +0100
GMT+10 +1000
GMT+11 +1100
GMT+12 +1200
GMT+2  +0200
GMT+3  +0300
GMT+4  +0400
GMT+5  +0500
GMT+6  +0600
GMT+7  +0700
GMT+8  +0800
GMT+9  +0900
GMT-1  -0100
GMT-10 -1000
GMT-11 -1100
GMT-12 -1200
GMT-13 -1300
GMT-14 -1400
GMT-2  -0200
GMT-3  -0300
GMT-4  -0400
GMT-5  -0500
GMT-6  -0600
GMT-7  -0700
GMT-8  -0800
GMT-9  -0900
GST    -0200
GYT    -0400
H      -0800
HDT    -0900
HKST   +0900
HKT    +0800
HOVST  +0800
HOVT   +0700
HST    -1000
I      -0900
ICT    +0700
IDDT   +0400
IDLE   +1200
IDLW   -1200
IDT    +0300
IOT    +0600
IRDT   +0430
IRST   +0330
ISST   +0000
IST    +0100
IT     +0330
JAVT   +0720
JCST   +0900
JDT    +1000
JST    +0900
JWST   +0800
K      -1000
KART   +0500
KDT    +1000
KOST   +1100
KST    +0900
KWAT   -1200
L      -1100
LHDT   +1100
LHST   +1030
LINT   +1400
M      -1200
MADMT  +0100
MADST  +0000
MADT   -0100
MALST  +0720
MALT   +0730
MART   -0930
MDDT   -0500
MDT    -0600
MEST   +0200
MESZ   +0200
MET    +0100
METDST +0200
MEWT   +0100
MEZ    +0100
MHT    +1200
MIST   +1100
MMT    +0630
MOST   +0900
MOT    +0800
MPT    -0600
MSD    +0400
MSK    +0300
MST    -0700
MUST   +0500
MUT    +0400
MVT    +0500
MWT    -0600
MYT    +0800
N      +0100
NCST   +1200
NCT    +1100
NDDT   -0130
NDT    -0230
NEGT   -0330
NEST   +0120
NET    +0020
NFST   +1230
NFT    +1100
NMT    +1112
NPT    +0545
NRT    +1200
NST    -0330
NT     -1100
NUT    -1100
NWT    -1000
NZDT   +1300
NZMT   +1130
NZST   +1200
NZT    +1200
O      +0200
P      +0300
PDDT   -0600
PDT    -0700
PEST   -0400
PET    -0500
PGT    +1000
PHOT   +1300
PHST   +0900
PHT    +0800
PKST   +0600
PKT    +0500
PMDT   -0200
PMST   -0300
PNT    -0830
PONT   +1100
PPMT   -0449
PPT    -0700
PST    -0800
PWT    +0900
PYST   -0300
PYT    -0400
Q      +0400
QMT    -0514
R      +0500
RET    +0400
ROK    +0900
S      +0600
SAST   +0200
SAT    -0400
SBT    +1100
SCT    +0400
SDMT   -0440
SDT    -1000
SGT    +0800
SMT    +0216
SRT    -0300
SST    -1100
SWAT   +0130
SWT    +0100
T      +0700
TAHT   -1000
TKT    +1300
TLT    +0900
TMT    +0139
TVT    +1200
U      +0800
ULAST  +0900
ULAT   +0800
UT     +0000
UTC    +0000
UYHST  -0230
UYST   -0200
UYT    -0300
V      +0900
VET    -0430
VUST   +1200
VUT    +1100
W      +1000
WAKT   +1200
WARST  -0300
WART   -0400
WAST   +0200
WAT    +0100
WEMT   +0200
WEST   +0100
WET    +0000
WFT    +1200
WGST   -0200
WGT    -0300
WIB    +0700
WIT    +0900
WITA   +0800
WMT    +0124
WSDT   +1400
WSST   +1300
X      +1100
XJT    +0600
Y      +1200
YDDT   -0700
YDT    -0800
YPT    -0800
YST    -0900
YWT    -0800
Z      +0000
ZP4    +0400
ZP5    +0500
ZP6    +0600

LICENSE

This script is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

AUTHOR

Sullivan Beck (sbeck@cpan.org)