rpm package
opensuse/perl-XML-Bare&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/perl-XML-Bare&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-57074 | Cri | 9.1 | < 0.53-bp160.2.1 | 0.53-bp160.2.1 | Jul 16, 2026 | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strin | |
| CVE-2026-13401 | Hig | 7.5 | < 0.53-bp160.2.1 | 0.53-bp160.2.1 | Jul 16, 2026 | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "" or |
- affected < 0.53-bp160.2.1fixed 0.53-bp160.2.1
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strin
- affected < 0.53-bp160.2.1fixed 0.53-bp160.2.1
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "" or