Description
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message.

The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and not_allowed, splice the submitted value into that string, and a failing type constraint puts the rejected value into the message it builds, which _apply_actions hands to add_error.

A field declared with a check regexp, a check list or a type constraint reaches those messages, with no custom validator and no non-default configuration. Errors rendered through an application's own escaping template layer rather than the library's rendering roles are not affected.

A request over the network that submits markup to such a field gets it back live inside the error span, running script in the victim's origin. Re-rendering a rejected value later gives the stored variant.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The flaw exists because HTML-FormHandler renders error messages by directly inserting the error string into HTML without any escaping. Two internal messages, named no_match and not_allowed, embed the user‑supplied value into the string, and a type constraint that fails also places the rejected value into the message built by _apply_actions. When an attacker submits markup to a field that uses a regular‑expression check, a check list, or a type constraint without a custom validator or altered configuration, the resulting error string is injected into the page exactly as submitted. The reflected cross‑site scripting vulnerability allows the execution of arbitrary scripts in the victim’s browser context, actions within the target domain.

Affected Systems

This vulnerability affects every installation of the Perl HTML‑FormHandler library with a version older than 0.410000. The issue is tied to the library’s own wrappers and renderers that interpolate error strings directly into HTML. Applications employing the library’s error rendering roles, or using a different error‑display mechanism that performs its own escaping, are not affected. Any application that relies on the default error rendering and provides unescaped values in form validation is vulnerable.

Risk and Exploitability

The vulnerability can be exploited via a normal form submission that triggers a validation failure. Based attacker would submit markup over the network to a field that uses a regular‑expression check, a check list, or a type constraint without a custom validator, causing the library to embed the unescaped value in an error string. This inferred attack vector exploits the library’s default error rendering. The EPSS score is < 1% and the KEV status is not listed, indicating a low overall probability of exploitation, but the clear path to reflected XSS and the fact that it does not require elevated privileges suggest a high risk to any user who interacts with such forms. The CVSS score of 6.1 signals medium severity, the reflected XSS flaw that permits arbitrary client‑side code execution.

Generated by OpenCVE AI on September 10, 2026 at 23:35 UTC.

Remediation

Vendor Solution

Upgrade to HTML-FormHandler 0.410000 or later.


OpenCVE Recommended Actions

  • Upgrade the HTML-FormHandler package to version 0.410000 or later to remove the unescaped error rendering bug.
  • If upgrading is not immediately feasible, configure your application to escape error strings before rendering. This can be achieved by using an alternate error rendering role or a custom template that applies proper HTML escaping to any user‑supplied content.
  • Review all form fields that rely on default validation (regular‑expression checks, check lists, type constraints) and add explicit validators or custom error messages that sanitize user input to prevent unescaped data from reaching the error output.

Generated by OpenCVE AI on September 10, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Gshank
Gshank html::formhandler
Vendors & Products Gshank
Gshank html::formhandler

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and not_allowed, splice the submitted value into that string, and a failing type constraint puts the rejected value into the message it builds, which _apply_actions hands to add_error. A field declared with a check regexp, a check list or a type constraint reaches those messages, with no custom validator and no non-default configuration. Errors rendered through an application's own escaping template layer rather than the library's rendering roles are not affected. A request over the network that submits markup to such a field gets it back live inside the error span, running script in the victim's origin. Re-rendering a rejected value later gives the stored variant.
Title HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message
Weaknesses CWE-79
References

Subscriptions

Gshank Html::formhandler
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-10T17:51:23.851Z

Reserved: 2026-08-14T12:49:19.665Z

Link: CVE-2026-19872

cve-icon Vulnrichment

Updated: 2026-09-08T22:07:16.768Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:17:29.850

Modified: 2026-09-10T18:17:58.827

Link: CVE-2026-19872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T13:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')