Description
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping.

The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escaped the equivalent values in the other layouts and wrappers, and 0.410002 extended that to these three.

Error messages that contain attacker-influenced content such as rejected field values could embed JavaScript in rendered pages.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The module fails to escape some error messages that are rendered directly into HTML. When an attacker supplies input that causes an error, the error string can contain malicious JavaScript which is then injected into the page. This cross‑site scripting flaw allows an attacker to execute arbitrary client‑side code in the context of the site, potentially leading to session hijacking, credential theft, or defacement.

Affected Systems

The vulnerability affects the Perl distribution HTML::FormHandler. All versions older than 0.410002 are compromised on any system that uses the Table form layout, or the Bootstrap 2 or Bootstrap 3 wrappers. Any deployment that relies on these layouts for form rendering must verify its module version and upgrade if necessary.

Risk and Exploitability

The CVSS score is 6.1, and the EPSS score is <1%, indicating a moderate severity and low exploitation probability. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a publicly accessible web form that uses the affected form layout; an attacker needs only to provide malicious input that triggers an error message. The unescaped error output would then be sent to the victim’s browser, enabling XSS. The exploit requires no special privileges beyond the ability to submit the form and view the resulting page.

Generated by OpenCVE AI on September 10, 2026 at 23:35 UTC.

Remediation

Vendor Solution

Upgrade to HTML-FormHandler 0.410002 or later.


OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading to HTML‑FormHandler 0.410002 or later.
  • If an upgrade is not immediately possible, configure your application to disable or replace any Table, Bootstrap 2, or Bootstrap 3 wrappers that echo error messages, ensuring that error strings are escaped or omitted.
  • Review any custom form templates or wrappers in your code base to verify that all user‑controlled error messages are properly escaped before rendering.

Generated by OpenCVE AI on September 10, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gshank
Gshank html::formhandler
Vendors & Products Gshank
Gshank html::formhandler

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escaped the equivalent values in the other layouts and wrappers, and 0.410002 extended that to these three. Error messages that contain attacker-influenced content such as rejected field values could embed JavaScript in rendered pages.
Title HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping
Weaknesses CWE-79
References

Subscriptions

Gshank Html::formhandler
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-10T17:49:22.429Z

Reserved: 2026-09-03T21:29:54.878Z

Link: CVE-2026-85485

cve-icon Vulnrichment

Updated: 2026-09-10T17:49:17.403Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:18:51.560

Modified: 2026-09-10T18:18:09.707

Link: CVE-2026-85485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')