Security Advisory

CVE-2026-57073

9.1
CRITICAL

Vulnerability Description

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "" without checking that the offsets are within the buffer. Truncated strings such as "
Published Date July 16, 2026
Official Source NIST NVD Advisory