Executive brief
HTML::Bare is a Perl library used for fast HTML parsing. A flaw in its parsing engine allows an attacker to cause a permanent denial-of-service by providing specially crafted, malformed HTML tags. When the library encounters these tags, it enters an infinite loop that consumes 100% of the CPU and cannot be interrupted by standard software signals, potentially crashing the application or making the server unresponsive.
Technical details
A vulnerability (CWE-835) exists in the hand-rolled C parser (parser.c) of HTML::Bare. The 'parserc_parse' function fails to advance the attribute-parse state cursor when encountering certain malformed attribute forms, such as nameless attributes or unbalanced quotes (e.g., "<a ='c'>"). Because the parser holds the Perl interpreter during the call, it cannot be interrupted by Perl-level signals like 'alarm'. An unauthenticated remote attacker can trigger this condition by submitting malicious HTML markup, resulting in indefinite CPU exhaustion. A patch has been proposed in the project's GitHub repository to ensure the cursor advances during these states.
Affected products
- CODECHILD HTML::Bare 0 through 0.04
Timeline
- 2026-07-15: other: Pull request with fix submitted to GitHub repository
- 2026-07-16: advisory: CVE-2026-13397 published