Executive brief
XML::Bare is a Perl library used for fast parsing of XML data. A flaw in its parsing engine allows an attacker to send specially crafted XML content that causes the application to freeze in an infinite loop. This results in a denial-of-service (DoS) condition where the affected system's processor becomes fully occupied, making the application unresponsive to other users.
Technical details
An infinite loop vulnerability (CWE-835) exists in the hand-rolled C parser (parser.c) of the XML::Bare Perl module. The root cause is located in the parserc_parse function, specifically within the att_nameqsdone state. When encountering malformed attribute forms—such as nameless attributes or unbalanced quotes—the parser fails to advance the state cursor (cpos) for characters other than '=' or NUL. Because the parser holds the Perl interpreter during execution, it cannot be interrupted by standard Perl signals like alarm(), allowing a single malicious XML string to pin a CPU core indefinitely. A patch is available via CPANSec and GitHub pull requests.
Affected products
- CODECHILD XML::Bare through 0.53
Timeline
- 2026-07-14: patched: Pull request submitted to GitHub repository
- 2026-07-16: disclosed: CVE published to NVD