Junglewise Threat Intelligence

CVE-2026-13401: XML::Bare infinite loop in parserc_parse attribute parsing

CVE-2026-13401 · Severity: info · CVSS 7.5 · Published 2026-07-16

Executive brief

XML::Bare is a Perl library used for fast parsing of XML data. A flaw in its parsing engine allows an attacker to send specially crafted XML content that causes the application to freeze in an infinite loop. This results in a denial-of-service (DoS) condition where the affected system's processor becomes fully occupied, making the application unresponsive to other users.

Technical details

An infinite loop vulnerability (CWE-835) exists in the hand-rolled C parser (parser.c) of the XML::Bare Perl module. The root cause is located in the parserc_parse function, specifically within the att_nameqsdone state. When encountering malformed attribute forms—such as nameless attributes or unbalanced quotes—the parser fails to advance the state cursor (cpos) for characters other than '=' or NUL. Because the parser holds the Perl interpreter during execution, it cannot be interrupted by standard Perl signals like alarm(), allowing a single malicious XML string to pin a CPU core indefinitely. A patch is available via CPANSec and GitHub pull requests.

Affected products

  • CODECHILD XML::Bare through 0.53

Timeline

  • 2026-07-14: patched: Pull request submitted to GitHub repository
  • 2026-07-16: disclosed: CVE published to NVD

References

Related threats