VYPR
Unrated severityNVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead

CVE-2026-57073

Description

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.

The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.

Truncated strings such as "<a/" can trigger an out-of-bounds read.

Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.