Cpanpm Project maintains a package manager for Perl that provides repository access and module installation across Perl development and deployment environments. The vendor's vulnerability footprint concentrates in the cpanpm tool itself and centers on improper certificate validation, a weakness class that affects the integrity of upstream module retrieval. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpanpm Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31484HIGH CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. | Apr 29, 2023 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpanpm Project.
Media articles that mention a CVE ID that affects a product developed by Cpanpm Project — matched by CVE ID, not by vendor name.