High severity7.5NVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026
CVE-2026-13401
CVE-2026-13401
Description
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes.
The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.
Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.
Affected products
3- Range: <=0.53
- osv-coords2 versionspkg:rpm/opensuse/perl-XML-Bare&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/perl-XML-Bare&distro=openSUSE%20Leap%2016.0
< 0.53-7.1+ 1 more
- (no CPE)range: < 0.53-7.1
- (no CPE)range: < 0.53-bp160.2.1
Patches
Vulnerability mechanics
References
3News mentions
1- Perl Modules Libyaml-syck-perl and Libxml-bare-perl Hit by Six Memory Corruption and DoS FlawsVypr Intelligence · Jul 17, 2026