{
"document": {
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "description",
"text": "HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as \"\" without checking that the offsets are within the buffer. Truncated strings such as \"0",
"product": {
"name": "HTML-Bare greater than 0",
"product_id": "CSAFPID-0001",
"product_identification_helper": {
"purl": "pkg:cpan/HTML-Bare"
}
}
}
],
"category": "product_name",
"name": "HTML-Bare"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-57073",
"cwe": {
"id": "CWE-125",
"name": "Out-of-bounds Read"
},
"notes": [
{
"category": "description",
"text": "HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.\n\nThe parserc_parse function attempts to check for multicharacter strings such as \"\" without checking that the offsets are within the buffer.\n\nTruncated strings such as \"