OESA-2026-2672

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2672
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2672.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2672
Upstream
  • CVE-2026-8829
Published
2026-06-12T12:27:07Z
Modified
2026-06-12T12:45:14.570097506Z
Summary
perl-HTML-Parser security update
Details

Objects of the HTML::Parser class will recognize markup and separate it from plain text (alias data content) in HTML documents. As different kinds of markup and text are recognized, the corresponding event handlers are invoked.

Security Fix(es):

HTML::Entities versions before 3.84 for Perl read freed heap memory in decodeentities.

The XS routine backing HTML::Entities::decodeentities cached a pointer (repl) into the entity-value SV returned by hvfetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to growgap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.

The read may disclose adjacent heap contents into the destination SV.(CVE-2026-8829)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP1 / perl-HTML-Parser

Package

Name
perl-HTML-Parser
Purl
pkg:rpm/openEuler/perl-HTML-Parser&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.81-2.oe2403sp1

Ecosystem specific

{
    "src": [
        "perl-HTML-Parser-3.81-2.oe2403sp1.src.rpm"
    ],
    "x86_64": [
        "perl-HTML-Parser-3.81-2.oe2403sp1.x86_64.rpm",
        "perl-HTML-Parser-debuginfo-3.81-2.oe2403sp1.x86_64.rpm",
        "perl-HTML-Parser-debugsource-3.81-2.oe2403sp1.x86_64.rpm",
        "perl-HTML-Parser-help-3.81-2.oe2403sp1.x86_64.rpm"
    ],
    "aarch64": [
        "perl-HTML-Parser-3.81-2.oe2403sp1.aarch64.rpm",
        "perl-HTML-Parser-debuginfo-3.81-2.oe2403sp1.aarch64.rpm",
        "perl-HTML-Parser-debugsource-3.81-2.oe2403sp1.aarch64.rpm",
        "perl-HTML-Parser-help-3.81-2.oe2403sp1.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2672.json"

openEuler:24.03-LTS-SP3 / perl-HTML-Parser

Package

Name
perl-HTML-Parser
Purl
pkg:rpm/openEuler/perl-HTML-Parser&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.81-2.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "perl-HTML-Parser-3.81-2.oe2403sp3.x86_64.rpm",
        "perl-HTML-Parser-debuginfo-3.81-2.oe2403sp3.x86_64.rpm",
        "perl-HTML-Parser-debugsource-3.81-2.oe2403sp3.x86_64.rpm",
        "perl-HTML-Parser-help-3.81-2.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "perl-HTML-Parser-3.81-2.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "perl-HTML-Parser-3.81-2.oe2403sp3.aarch64.rpm",
        "perl-HTML-Parser-debuginfo-3.81-2.oe2403sp3.aarch64.rpm",
        "perl-HTML-Parser-debugsource-3.81-2.oe2403sp3.aarch64.rpm",
        "perl-HTML-Parser-help-3.81-2.oe2403sp3.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2672.json"

openEuler:20.03-LTS-SP4 / perl-HTML-Parser

Package

Name
perl-HTML-Parser
Purl
pkg:rpm/openEuler/perl-HTML-Parser&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.73-2.oe2003sp4

Ecosystem specific

{
    "src": [
        "perl-HTML-Parser-3.73-2.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "perl-HTML-Parser-3.73-2.oe2003sp4.x86_64.rpm",
        "perl-HTML-Parser-debuginfo-3.73-2.oe2003sp4.x86_64.rpm",
        "perl-HTML-Parser-debugsource-3.73-2.oe2003sp4.x86_64.rpm",
        "perl-HTML-Parser-help-3.73-2.oe2003sp4.x86_64.rpm"
    ],
    "aarch64": [
        "perl-HTML-Parser-3.73-2.oe2003sp4.aarch64.rpm",
        "perl-HTML-Parser-debuginfo-3.73-2.oe2003sp4.aarch64.rpm",
        "perl-HTML-Parser-debugsource-3.73-2.oe2003sp4.aarch64.rpm",
        "perl-HTML-Parser-help-3.73-2.oe2003sp4.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2672.json"

openEuler:22.03-LTS-SP4 / perl-HTML-Parser

Package

Name
perl-HTML-Parser
Purl
pkg:rpm/openEuler/perl-HTML-Parser&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.78-2.oe2203sp4

Ecosystem specific

{
    "src": [
        "perl-HTML-Parser-3.78-2.oe2203sp4.src.rpm"
    ],
    "x86_64": [
        "perl-HTML-Parser-3.78-2.oe2203sp4.x86_64.rpm",
        "perl-HTML-Parser-debuginfo-3.78-2.oe2203sp4.x86_64.rpm",
        "perl-HTML-Parser-debugsource-3.78-2.oe2203sp4.x86_64.rpm",
        "perl-HTML-Parser-help-3.78-2.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "perl-HTML-Parser-3.78-2.oe2203sp4.aarch64.rpm",
        "perl-HTML-Parser-debuginfo-3.78-2.oe2203sp4.aarch64.rpm",
        "perl-HTML-Parser-debugsource-3.78-2.oe2203sp4.aarch64.rpm",
        "perl-HTML-Parser-help-3.78-2.oe2203sp4.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2672.json"