Resource Exhaustion Vulnerability in HtmlArea Field for Perl by HANK
CVE-2026-13051

Currently unrated

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-13051?

A resource exhaustion vulnerability in the HtmlArea field of the Form::Processor module for Perl allows attackers to execute crafted markup submissions that can lead to unhandled exceptions or excessive memory allocation. This occurs through manipulated HTML::Tidy diagnostics which pass invalid messages to the add_error method. The resulting method calls on the language handle can be exploited by attackers to perform unintended actions, exposing applications relying on this module to risks if an attacker utilizes specially crafted input.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.