Security Advisories (2)
CVE-2026-13401 (2026-07-16)

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

CVE-2026-57074 (2026-07-16)

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read.

Changes for version 0.49

  • Fixes to find_by_perl Can now be accessed in an object or namespace flexibly. Now ignores case of keys. Keys with underscores can be used. Will work properly when passed a single node instead of an array reference of nodes.
  • Fixes to xget Method of deferencing has been changed to be compatible with newer versions of perl ( 5.10.2+ )
  • Fixed handling of nodes named 'value'; they will no longer crash the XS code
  • Added a new function similar to new called 'simple', that works in the same way but automatically uses the 'simple' parser
  • Altered handling of node values in simple mode, so that it stores values when mixed with nodes or atttributes under 'content' ( like XML::Simple ) This feature was requested by users so it has been added. Note that it only does this when the value is not composed of just spaces and carriage returns.

Modules

Minimal XML parser implemented via a C state engine

Provides

in Bare.pm