VYPR

perl-HTML-Bare

by Nanoscopic

CVEs (2)

  • CVE-2026-57073Jul 16, 2026
    risk 0.00cvss epss 0.00

    HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated…

  • CVE-2026-13397Jul 16, 2026
    risk 0.00cvss epss 0.00

    HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as ""…