CVE-2025-15646Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses. Any caller that runs parse() with the default format => 'string', or with format => 'tree', on input containing a <template> element serializes the over-read bytes into the returned result, disclosing bounded heap contents. format => 'callback' reaches a croak on the unhandled node type and is unaffected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-02); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-05: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-05: 107-0207-05
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-021
Patch1
2026-07-051
Disclosure1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN July 2026 disclosures CVE-2026-56016: CGI::Session::ID::md5 before 4.49 generate predictable session ids from low-entropy sources https://www.openwall.com/lists/oss-security/2026/07/01/6 CVE-2025-15646: HTML::Gumbo before 0.19 disclose heap memory via type confusion https://www.openwall.com/lists/oss-security/2026/07/01/7

    Post summary

    Two Perl CPAN modules were newly disclosed: CGI::Session::ID::md5 uses predictable session IDs, while HTML::Gumbo may leak heap memory via type confusion.

    101912.2K
    4.7K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🧩 CVE-2025-15646: HTML::Gumbo for Perl (before 0.19) exposes heap memory via type confusion in walk_tree. Missing &lt;template&gt; element handling since 2015. CVSS 9.8 critical. Update to 0.19 now. #perl #infosec https://secalerts.co/vulnerability/CVE-2025-15646?utm_campaign=x https://t.co/swM9MV9YlJ

    Post summary

    The tweet announces the CVE-2025-15646 vulnerability in HTML::Gumbo, provides technical details, and urges users to update to version 0.19 to mitigate the critical issue.

    0000059
    846 followersView on X

Explore more