CVE-2026-3031 Details
Description
Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project.
A vulnerability exists in Image::EPEG for Perl, specifically in versions through 0.15, due to the inclusion of an outdated and unsupported version of the Epeg library. This version, Epeg 0.9.0, was last updated in 2004 and is embedded within the Image::EPEG distribution. Epeg is a JPEG thumbnail library that was previously part of the Enlightenment Project.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://backpan.metacpan.org/authors/id/T/TO/TOKUHIROM/Image-Epeg-0.15.readme | CPANSec | Broken LinkVendor |
| https://backpan.metacpan.org/authors/id/T/TO/TOKUHIROM/Image-Epeg-0.15.tar.gz | CPANSec | Broken LinkSource CodeVendor |
| https://sourceforge.net/projects/enlightenment/files/OldFiles/epeg-0.9.0.tar.gz/download | CPANSec | Broken LinkSource Code |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1104 | Use of Unmaintained Third Party Components | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| Image::EPEG | <= 0.15 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | New CVE Received | CPANSec |
Volerion