Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-13401

Опубликовано: 16 июл. 2026
Источник: debian
EPSS Низкий

Описание

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml-bare-perlfixed0.53-5package
libxml-bare-perlno-dsatrixiepackage
libxml-bare-perlpostponedbookwormpackage
libxml-bare-perlpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/41876829/

  • https://github.com/nanoscopic/perl-XML-Bare/pull/2

  • https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-13401-r1.patch

EPSS

Процентиль: 32%
0.00388
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

CVSS3: 7.5
nvd
около 1 месяца назад

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

CVSS3: 7.5
github
около 1 месяца назад

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

suse-cvrf
около 1 месяца назад

Security update for perl-XML-Bare

suse-cvrf
28 дней назад

Security update for perl-XML-Bare

EPSS

Процентиль: 32%
0.00388
Низкий