Security Advisory

CVE-2026-57074

9.1
CRITICAL

Vulnerability Description

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "" without checking that the offsets are within the buffer. Truncated strings such as "
Published Date July 16, 2026
Official Source NIST NVD Advisory