CRITICAL
BPS
CVE published 2026-07-01
CVE-2025-15646
CVE-2025-15646 is a critical vulnerability in HTML::Gumbo versions before 0.19 for Perl, which discloses heap memory via type confusion. The vulnerability arises from the lack of support for the <template> element in the walk_tree function, leading to strlen() over-reading the heap block. This results in the disclosure of bounded heap contents when parse() is called with default or 'tree' format on input [truncated]