Vulnerability Description
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/nanoscopic/perl-XML-Bare/pull/2
- https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-13401-r1.patch
- http://www.openwall.com/lists/oss-security/2026/07/16/2
FAQ
What is CVE-2026-13401?
CVE-2026-13401 is a vulnerability with a CVSS score of 7.5 (HIGH). XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malform...
How severe is CVE-2026-13401?
CVE-2026-13401 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13401?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.