CPANSA-HTML-Bare-2026-13397: HTML-Bare vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2026-07-16T00:00:00 Engine CSAF Perl Toolkit 0.26
Current release date 2026-07-16T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score 7.5 Severity
Original language Language en
Also referred to

Vulnerability Description

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "" or unbalanced quotes "" can trigger this condition. Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.

Vulnerabilities

CVE-2026-13397

Vulnerability Description

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes.

The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.

Nameless attributes such as "
" or unbalanced quotes "" can trigger this condition.

Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.

Weakness CWE-835 : Loop with Unreachable Exit Condition ('Infinite Loop')

Product status

Known affected
Product Score
HTML-Bare greater than 0
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity
3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 High

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Thu Jul 16 00:00:00 2026 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/