Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-14030

29
FAUCET Score

CVE-2024-14030 details a buffer overwrite vulnerability in Sereal::Decoder versions 4.000 through 4.009_002 for Perl, originating from an embedded Zstandard library (CVE-2019-11922) containing a race condition. Rated 8.1 HIGH (CVSS:3.1), this flaw allows for out-of-bounds writes via a network attack vector with high attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. Exploitation could occur if an output buffer smaller than recommended is used. There is currently no evidence of active exploitation, nor is any public exploit code available. Community discussion and media coverage are minimal, and its EPSS score is very low, indicating limited current attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.000, < 4.010CPE matchmatch criteria
cpe:2.3:a:yves:sereal\:\:decoder:*:*:*:*:*:perl:*:*
>= 4.000, <= 4.009_002CPE match
cpe:2.3:a:yves:sereal\:\:decoder:*:*:*:*:*:perl:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 6th percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / advisories/GHSA-w77f-wv46-4vcx
Not Applicable
metacpan.org / release/YVES/Sereal-Decoder-4.010/changes
Release Notes
cve.org / CVERecord
Not Applicable