XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes.
The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.
Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.
The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.
Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Apply the patch.
References
History
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codechild
Codechild xml::bare |
|
| Vendors & Products |
Codechild
Codechild xml::bare |
Fri, 17 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 16 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition. | |
| Title | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes | |
| Weaknesses | CWE-835 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-07-17T12:51:52.550Z
Reserved: 2026-06-26T08:38:33.750Z
Link: CVE-2026-13401
Updated: 2026-07-16T19:27:57.805Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T22:10:07Z
Weaknesses