CVE-2026-8829

Basic Information

Severity UNKNOWN
Base Score N/A
CNA CPANSec
Published Date 2026-06-03 22:03:46 UTC
Last Modified 2026-06-03 22:03:46 UTC
CVE.org Link https://www.cve.org/CVERecord?id=CVE-2026-8829
NVD https://nvd.nist.gov/vuln/detail/CVE-2026-8829

Description

HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation. The read may disclose adjacent heap contents into the destination SV.

Affected Products

Vendor Product
oalders html::entities