Junglewise Threat Intelligence

CVE-2026-8829: libwww-perl HTML::Entities use-after-free in _decode_entities

CVE-2026-8829 · Severity: info · CVSS 0 · Published 2026-06-04

Executive brief

HTML::Entities is a Perl library used to convert characters to and from their HTML entity equivalents (like converting '&' to '&'). A security flaw in how it handles memory during decoding could allow an attacker to read sensitive information from the computer's memory. This occurs when the library processes specially crafted input that causes it to read data from memory locations it has already released, potentially exposing data from other operations.

Technical details

A use-after-free vulnerability exists in the XS routine backing HTML::Entities::_decode_entities. The routine caches a pointer (repl) into an entity-value Scalar Value (SV) returned by hv_fetch. If the input SV is identical to a value SV in the entity2char hash and contains its own key as an entity reference, a subsequent call to grow_gap() may reallocate the SV's PV buffer. This realloc frees the memory that the 'repl' pointer still references. When the routine later performs a copy loop, it reads from this freed memory, potentially disclosing adjacent heap contents into the destination SV. The issue is fixed in version 3.84 by ensuring the entity value is copied into an owned buffer when self-aliasing is detected.

Affected products

  • libwww-perl HTML::Entities (HTML-Parser) before 3.84

Timeline

  • 2026-05-19: patched: Fix committed to master branch and pull request merged.
  • 2026-06-04: disclosed: CVE published to NVD.

References