Security Advisories (2)
CVE-2026-57074 (2026-07-16)

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read.

CVE-2026-13401 (2026-07-16)

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

Changes for version 0.47 - 2012-02-08

  • Preping release unchanged from trial release. The 0.45 release and previous set particular compile options for several different platforms. My release refactoring stripped the Makefile.PL customisations, however it appears these are not needed by any of the smoker CPANTS systems, so am releasing with really basic compilation driver - see how it goes...

Changes for version 0.46_03 - 2012-01-28

  • Bug #49906 Simple mode reports content of empty node as integer 1
  • Bug #52762 XML::Simple compatibility mode doesn't support CDATA with attributes
  • Bug #52832 Several memory leaks
  • XML quote decoding on XML read

Modules

Minimal XML parser implemented via a C state engine UNAUTHORIZED