VYPR
High severity7.5NVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026

CVE-2026-13401

CVE-2026-13401

Description

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes.

The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.

Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.

Affected products

3

Patches

Vulnerability mechanics

References

3

News mentions

1