Security Advisories (2)
CVE-2026-13401 (2026-07-16)

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

CVE-2026-57074 (2026-07-16)

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read.

Changes for version 0.24

  • Continued makefile.pl changes to recognize some platforms use executable extensions for gcc.
  • Continued XS changed to attempt Perl 5.5.5 compatibility. ( will setup a test platform and do more testing before the next release, so I wouldn't consider these changes ensuring 5.5.5 compatibility quite yet )
  • Remove blank require line from meta.yml. It seemed to break the kwalitee rating.

Modules

Minimal XML parser implemented via a C state engine