๐Ÿ” CVE Alert

CVE-2026-57074

CRITICAL 9.1

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead

CVSS Score
9.1
EPSS Score
0.2%
EPSS Percentile
8th

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read.

CWE CWE-125
Vendor codechild
Product xml::bare
Published Jul 16, 2026
Last Updated Jul 17, 2026
Stay Ahead of the Next One

Get instant alerts for codechild xml::bare

Be the first to know when new critical vulnerabilities affecting codechild xml::bare are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CODECHILD / XML::Bare
0 โ‰ค 0.53

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nanoscopic/perl-XML-Bare/pull/1 security.metacpan.org: https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-57074-r1.patch openwall.com: http://www.openwall.com/lists/oss-security/2026/07/16/1