CPANSA-XML-Bare-2026-13401: XML-Bare vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-07-16T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-07-16T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 7.5 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.
Vulnerabilities
CVE-2026-13401
Vulnerability DescriptionXML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes.
The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.
Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.
| Weakness | CWE-835 : Loop with Unreachable Exit Condition ('Infinite Loop') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| XML-Bare greater than 0 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-XML-Bare-2026-13401 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-xml-bare-2026-13401.json - https://github.com/nanoscopic/perl-XML-Bare/pull/2 external
https://github.com/nanoscopic/perl-XML-Bare/pull/2 - https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-13401-r1.patch external
https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-13401-r1.patch - http://www.openwall.com/lists/oss-security/2026/07/16/2 external
http://www.openwall.com/lists/oss-security/2026/07/16/2 - CVE-2026-13401 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-13401
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Thu Jul 16 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/