The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.
Truncated strings such as "<a/" can trigger an out-of-bounds read.
Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Apply the patch to version 0.02 (from CPAN) or version 0.04 (from the git repository).
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codechild
Codechild html::bare |
|
| Vendors & Products |
Codechild
Codechild html::bare |
Fri, 17 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 16 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read. Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository. | |
| Title | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead | |
| Weaknesses | CWE-125 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-07-17T12:44:26.715Z
Reserved: 2026-06-23T17:59:40.467Z
Link: CVE-2026-57073
Updated: 2026-07-16T19:27:58.902Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T22:10:05Z