Resource Exhaustion Vulnerability in HtmlArea Field for Perl by HANK
CVE-2026-13051
Currently unrated
What is CVE-2026-13051?
A resource exhaustion vulnerability in the HtmlArea field of the Form::Processor module for Perl allows attackers to execute crafted markup submissions that can lead to unhandled exceptions or excessive memory allocation. This occurs through manipulated HTML::Tidy diagnostics which pass invalid messages to the add_error method. The resulting method calls on the language handle can be exploited by attackers to perform unintended actions, exposing applications relying on this module to risks if an attacker utilizes specially crafted input.
