PT-2026-60504 · Codechild · Html::Bare

CVE-2026-57073

·

Published

2026-07-16

·

Updated

2026-07-19

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.
The parserc parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.
Truncated strings such as "<a/" can trigger an out-of-bounds read.
Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57073

Affected Products

Html::Bare