CVE Explorer
CVE-2026-8829
HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.
The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent co
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"HTML-Parser","product":"HTML::Entities","programFiles":["util.c"],"programRoutines":[{"name":"HTML::Entities::_decode_entities"}],"repo":"https://github.com/libwww-perl/HTML-Parser","vendor":"OALDERS","versions":[{"lessThan":"3.84","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7f1439a272c357d59c796cc9941949a56b22d01cf14a5282729b28b97702bb3a · sha256:30a7ab20e9963516… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7f1439a272c357d59c796cc9941949a56b22d01cf14a5282729b28b97702bb3a · sha256:30a7ab20e9963516… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-416","description":"CWE-416 Use After Free","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7f1439a272c357d59c796cc9941949a56b22d01cf14a5282729b28b97702bb3a · sha256:30a7ab20e9963516… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/06/04/2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7f1439a272c357d59c796cc9941949a56b22d01cf14a5282729b28b97702bb3a · sha256:30a7ab20e9963516… · /containers/adp/0/references/0
{"tags":["patch"],"url":"https://github.com/libwww-perl/HTML-Parser/commit/6922552b0778c90a9587a3894e248be4d3a25e1c.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7f1439a272c357d59c796cc9941949a56b22d01cf14a5282729b28b97702bb3a · sha256:30a7ab20e9963516… · /containers/cna/references/1
{"tags":["patch"],"url":"https://github.com/libwww-perl/HTML-Parser/pull/56"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7f1439a272c357d59c796cc9941949a56b22d01cf14a5282729b28b97702bb3a · sha256:30a7ab20e9963516… · /containers/cna/references/0
{"url":"https://lists.debian.org/debian-lts-announce/2026/06/msg00044.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7f1439a272c357d59c796cc9941949a56b22d01cf14a5282729b28b97702bb3a · sha256:30a7ab20e9963516… · /containers/adp/0/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.