PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15646 BPS CVE debrief

CVE-2025-15646 is a critical vulnerability in HTML::Gumbo versions before 0.19 for Perl, which discloses heap memory via type confusion. The vulnerability arises from the lack of support for the <template> element in the walk_tree function, leading to strlen() over-reading the heap block. This results in the disclosure of bounded heap contents when parse() is called with default or 'tree' format on input containing a <template> element.

Vendor
BPS
Product
HTML::Gumbo
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-01
Original CVE updated
2026-10-06
Advisory published
2026-07-01
Advisory updated
2026-10-06

Who should care

Defenders responsible for systems using HTML::Gumbo versions before 0.19, especially those handling user-inputted HTML content, should assess exposure and verify inventory. Operators of affected systems, vulnerability management teams, and security teams should prioritize verifying inventory and assessing exposure to ensure the security of their environments.

Why it matters

CVE-2025-15646 is a critical vulnerability in HTML::Gumbo versions before 0.19 for Perl, disclosing heap memory via type confusion. Defenders should prioritize assessing exposure and verifying inventory for systems using affected versions, especially those handling user-inputted HTML content.

  • Potential disclosure of sensitive heap memory contents
  • Verification of inventory and exposure for affected systems
  • Prioritization of upgrades to HTML::Gumbo version 0.19 or later
  • Monitoring for potential exploitation attempts

Technical summary

The walk_tree function in lib/HTML/Gumbo.xs was not updated to support the <template> element, leading to type confusion and strlen() over-reading the heap block. This results in the disclosure of bounded heap contents when parse() is called with default or 'tree' format on input containing a <template> element. The vulnerability arises from the lack of support for the <template> element, which was added to libgumbo 0.10.0 in 2015. Any caller that runs parse() with the default format => 'string', or with format => 'tree', on input containing a <template> element serializes the over-read bytes into the returned result.

Defensive priority

Defenders should prioritize assessing exposure and verifying inventory for systems using HTML::Gumbo versions before 0.19, especially those handling user-inputted HTML content.

Recommended defensive actions

  • Assess exposure and verify inventory for systems using HTML::Gumbo versions before 0.19
  • Verify if user-inputted HTML content is handled by affected systems
  • Consider upgrading to HTML::Gumbo version 0.19 or later
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability details are based on the CVE record and source references. However, the exact scope of affected systems and versions requires verification from official sources. Defenders should verify inventory, assess exposure, and monitor for exploitation attempts. The lack of support for the <template> element in the walk_tree function leads to type confusion and strlen() over-reading the heap block, disclosing bounded heap contents.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15646 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15646

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15646 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15646

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://bugs.debian.org/1104789

    9b29abf9-4ab0-4765-b253-1875cd9b441e

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bestpractical/HTML-Gumbo/commit/15c0598909d4a64f47ef0a1abc5051f4e113c186.patch

    9b29abf9-4ab0-4765-b253-1875cd9b441e

  • Source reference

    Unverified legacy reference

    URL: https://metacpan.org/release/BPS/HTML-Gumbo-0.19/changes

    9b29abf9-4ab0-4765-b253-1875cd9b441e

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.