Unrated severityNVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead
CVE-2026-57073
Description
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.
Truncated strings such as "<a/" can trigger an out-of-bounds read.
Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.
Affected products
2- Range: <=0.04
- Range: <=0.04
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.