Security Advisories (2)
CVE-2026-13401 (2026-07-16)

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

CVE-2026-57074 (2026-07-16)

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read.

Changes for version 0.48

  • Revert code back to 0.45 version Changes lost in the process: Content is not stored in the 'content' key any more; it is stored as the node itself when the node contains nothing else. As God intended. Memory leak fixes Quote handling
  • Code copyright returned fully to David Helkowski; any changes by other parties have been discarded. Any code ported in from other open source projects removed. This has been done intentionally so as to make it possible to relicense the software commerically.
  • XS code modofied to work in a multi-threaded environment
  • Reverting Makefile.PL back to original wierd hackish fixes. They are there for specific reasons.

Modules

Minimal XML parser implemented via a C state engine