The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.
Truncated strings such as "<a/" can trigger an out-of-bounds read.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Apply the patch.
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codechild
Codechild xml::bare |
|
| Vendors & Products |
Codechild
Codechild xml::bare |
Fri, 17 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 16 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read. | |
| Title | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead | |
| Weaknesses | CWE-125 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-07-17T18:07:06.943Z
Reserved: 2026-06-23T17:59:40.467Z
Link: CVE-2026-57074
Updated: 2026-07-16T19:27:59.991Z
Status : Deferred
Published: 2026-07-16T17:16:58.213
Modified: 2026-07-17T19:17:17.263
Link: CVE-2026-57074
No data.
OpenCVE Enrichment
Updated: 2026-08-03T03:00:04Z