String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service (CVE-2026-14895) | HOL Guard CVE