XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes.
A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer because Perl's read() returns decoded characters while SvPV() gives back multi-byte UTF-8 bytes that can exceed the pre-allocated buffer size. This can cause heap corruption (double free or corruption) and crashes.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade perl-XML-Parser | Apr 16, 2026 | Apr 13, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-XML-ParserUpgrade perl-XML-Parser-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-XML-ParserUpgrade perl-XML-Parser-testsUpgrade perl-XML-Parser-debuginfoUpgrade perl-XML-Parser-debugsource | Apr 14, 2026 | Mar 19, 2026 |
| Debian | — | Upgrade libxml-parser-perl | Mar 23, 2026 | Mar 23, 2026 |
| Oracle_linux | — | Upgrade perl-XML-Parser | Apr 22, 2026 | Mar 19, 2026 |
| Redhat_linux | — | No solution existsUpgrade perl-XML-Parser-debuginfoUpgrade perl-XML-ParserUpgrade perl-XML-Parser-debugsource | Apr 14, 2026 | Mar 19, 2026 |
| Rocky_linux | — | Upgrade perl-XML-Parser-debugsourceUpgrade perl-XML-ParserUpgrade perl-XML-Parser-debuginfo | Apr 15, 2026 | Apr 14, 2026 |
| Suse | — | Upgrade perl-XML-Parser | Sep 1, 2026 | Mar 19, 2026 |
| Ubuntu | — | Upgrade libxml-parser-perl | Apr 15, 2026 | Mar 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub