LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-13051

Published
CVSS9.1
Severitycritical
WeaknessCWE-470
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting message to add_error as its first argument, which add_error hands to the language handle as the Locale::Maketext message key. The default handle's lexicon sets `_AUTO`, so a message that is not a lexicon entry is compiled as a bracket notation template instead of being looked up. Tidy diagnostics quote the offending attribute name or value, so a bracket group in the submitted markup

References

← Back to the CVE Tracker

Our coverage of CVE-2026-13051

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-13051.