CVE-2026-8829

EUVD-2026-34194
HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.

The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.

The read may disclose adjacent heap contents into the destination SV.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
Affected Products (NVD)
VendorProductVersion
oaldershtml\
𝑥
< 3.84
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libhtml-parser-perl
bookworm
3.81-1+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
3.75-1+deb11u1
fixed
forky
3.83-2
fixed
sid
3.83-2
fixed
trixie
3.83-2~deb13u1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-HTML-Parser
Amazon Linux 2
0:3.71-4.amzn2.0.3
fixed
Amazon Linux 2023
0:3.76-1.amzn2023.0.4
fixed
perl-HTML-Parser-debuginfo
Amazon Linux 2
0:3.71-4.amzn2.0.3
fixed
Amazon Linux 2023
0:3.76-1.amzn2023.0.4
fixed
perl-HTML-Parser-debugsource
Amazon Linux 2023
0:3.76-1.amzn2023.0.4
fixed
perl-HTML-Parser-tests
Amazon Linux 2023
0:3.76-1.amzn2023.0.4
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
perl-HTML-Parser
Azure Linux 3.0
0:3.82-2.azl3
fixed