Junglewise Threat Intelligence

CVE-2026-19873: HTML::FormFu resource exhaustion via unbounded repeat count

CVE-2026-19873 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

HTML::FormFu is a Perl library for building and processing web forms. A vulnerability allows attackers to trigger resource exhaustion (CPU and memory exhaustion) by manipulating form query parameters. An attacker can send a simple GET request with a large repeat count parameter to exhaust server resources without authentication, potentially causing denial of service.

Technical details

The vulnerability is a resource exhaustion (DoS) issue in the Repeatable element's process method. When a Repeatable element has counter_name set, it reads the repeat count directly from the query string parameter, validating only that it is a positive integer, but imposes no upper limit. The repeat() method then deep-clones the element's child subtree once per iteration. The count is processed on every request before the form determines if it was submitted, allowing unauthenticated GET requests to trigger the clone loop. The cost is super-linear because each cloned field's constraints call _find_field_value, which walks the entire element tree once per constraint—doubling the parameter multiplies CPU consumption 4–5x. Nested Repeatables compound the problem: outer_count=100 and inner_count=100 creates 10,000 fields consuming ~95 MB of memory from a single request. The latest CPAN release is 2.07 from 2018; version 2.08 exists only in git.

Affected products

  • FormFu HTML::FormFu through 2.08

Timeline

  • 2026-08-31: disclosed
  • 2026-08-31: advisory

References