{ "document": { "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "description", "text": "XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as \"\" without checking that the offsets are within the buffer. Truncated strings such as \"0", "product": { "name": "XML-Bare greater than 0", "product_id": "CSAFPID-0001", "product_identification_helper": { "purl": "pkg:cpan/XML-Bare" } } } ], "category": "product_name", "name": "XML-Bare" } ] }, "vulnerabilities": [ { "cve": "CVE-2026-57074", "cwe": { "id": "CWE-125", "name": "Out-of-bounds Read" }, "notes": [ { "category": "description", "text": "XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.\n\nThe parserc_parse function attempts to check for multicharacter strings such as \"\" without checking that the offsets are within the buffer.\n\nTruncated strings such as \"