# CVE-2024-14030

## Summary

- **CVE ID:** CVE-2024-14030
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-1395
- **Published:** Mar 31, 2026
- **Last Modified:** Mar 31, 2026

## Description

Sereal::Decoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library.

Sereal::Decoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922.  This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

## Affected Products

- YVES — Sereal::Decoder (4.000)

## References

- [CNA](https://github.com/advisories/GHSA-w77f-wv46-4vcx)
- [CNA](https://www.cve.org/CVERecord?id=CVE-2019-11922)
- [CNA](https://metacpan.org/release/YVES/Sereal-Decoder-4.010/changes)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.36%
- **EPSS Percentile:** 28.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._