HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.
The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.
The read may disclose adjacent heap contents into the destination SV.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade perl-HTML-Parser-debuginfoUpgrade perl-HTML-Parser | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-HTML-Parser-debuginfoUpgrade perl-HTML-ParserUpgrade perl-HTML-Parser-testsUpgrade perl-HTML-Parser-debugsource | Jun 23, 2026 | Jun 4, 2026 |
| Debian | — | Upgrade libhtml-parser-perl | Jun 29, 2026 | Jun 29, 2026 |
| Ibm Aix | — | Apply the fix or workaround for aix_vios_advisory | Aug 16, 2026 | Aug 14, 2026 |
| Ubuntu | — | Upgrade libhtml-parser-perl | Jul 22, 2026 | Jun 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub