Junglewise Threat Intelligence

CVE-2025-15646: BPS HTML::Gumbo type confusion in walk_tree

CVE-2025-15646 · Severity: info · CVSS 0 · Published 2026-07-01

Vendors: Best Practical Solutions.

Executive brief

HTML::Gumbo is a Perl library used to parse HTML documents. A vulnerability exists where processing a specially crafted HTML file containing a <template> tag can cause the library to read and disclose sensitive information from the server's memory. This could allow an attacker to see fragments of other users' data or internal system information that happens to be stored in the application's memory at that time.

Technical details

A type confusion vulnerability exists in the walk_tree function within lib/HTML/Gumbo.xs. When libgumbo introduced the GUMBO_NODE_TEMPLATE node type, the Perl wrapper was not updated to handle it, causing it to fall through to a code path intended for text nodes. Because template nodes use the GumboElement structure rather than GumboText, the application performs a strlen() operation on incompatible memory, leading to an out-of-bounds heap read. An attacker can exploit this by providing HTML input containing <template> tags, which causes the parser to serialize adjacent heap memory into the returned string or tree result. The vulnerability is fixed in version 0.19.

Affected products

  • BPS (Best Practical Solutions) HTML::Gumbo before 0.19

Timeline

  • 2025-05-06: disclosed: Initial report in Debian bug tracker
  • 2025-05-17: patched: Fix committed to upstream repository
  • 2026-07-01: advisory: CVE published to NVD

References