CVE-2026-60074 Details
Description
Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction. Any caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed.
A vulnerability exists in Date::Manip versions through 6.99 for Perl, where the library can return corrupted dates when non-ASCII decimal digits are used. The issue arises because the parsing regex captures numeric values using a shorthand that includes all Unicode decimal digits, not just ASCII. This allows for exploitation by crafting a date string that includes non-ASCII digits, which can bypass numeric range validations and lead to incorrect date calculations. Such discrepancies can go unnoticed, especially when the parsed date is used in logical checks, like expiry or retention assessments.
Users can upgrade to Date::Manip version 7.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SBECK-github/Date-Manip/pull/54 | CPANSec | |
| https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Base.pm#L602-614 | CPANSec | Source CodeVendor |
| https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1536-1539 | CPANSec | Source CodeVendor |
| https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch | CPANSec | Broken LinkSource CodeVendor |
| http://www.openwall.com/lists/oss-security/2026/07/30/19 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1289 | Improper Validation of Unsafe Equivalence in Input | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| Date::Manip | <= 6.99 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | CPANSec |
| Sep 2, 2026 | CVE Modified | CVE |
| Aug 21, 2026 | CVE Modified | CPANSec |
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | CVE Modified | CVE |
| Jul 30, 2026 | New CVE Received | CPANSec |
Volerion