The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.
Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Apply the patch.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codechild
Codechild xml::bare |
|
| Vendors & Products |
Codechild
Codechild xml::bare |
Fri, 17 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 16 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition. | |
| Title | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes | |
| Weaknesses | CWE-835 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-07-17T12:51:52.550Z
Reserved: 2026-06-26T08:38:33.750Z
Link: CVE-2026-13401
Updated: 2026-07-16T19:27:57.805Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-25T05:30:17Z