Advisories ยป MGASA-2026-0283

Updated perl-JavaScript-Minifier-XS package fixes security vulnerabilities

Publication date: 20 Jul 2026
Modification date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56017 , CVE-2026-56018

Description

The updated package fixes security vulnerabilities:
JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL
pointer dereference when the first meaningful token of the input is a
slash. (CVE-2026-56017)
JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on
every call to minify(), allowing unbounded memory growth.
(CVE-2026-56018)
                

References

SRPMS

10/core

9/core