Critical severity9.1NVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026
CVE-2026-57074
CVE-2026-57074
Description
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.
Truncated strings such as "<a/" can trigger an out-of-bounds read.
Affected products
3- Range: <=0.53
- osv-coords2 versionspkg:rpm/opensuse/perl-XML-Bare&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/perl-XML-Bare&distro=openSUSE%20Tumbleweed
< 0.53-bp160.2.1+ 1 more
- (no CPE)range: < 0.53-bp160.2.1
- (no CPE)range: < 0.53-7.1
Patches
Vulnerability mechanics
References
3News mentions
1- Perl Modules Libyaml-syck-perl and Libxml-bare-perl Hit by Six Memory Corruption and DoS FlawsVypr Intelligence · Jul 17, 2026