CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements

Published Aug 31, 2026
·
Updated

HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements.

When a Repeatable element has countername set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer, and passes it to repeat, which deep-clones the element's child subtree once per iteration. Nothing caps the value, and no attribute lets an application impose a limit.

The count is read on every request, before the form decides whether it was submitted, so a plain GET reaches the clone loop with no credentials, no session and no request body. Nesting multiplies: a Repeatable inside a Repeatable takes a counter at each level, so an outer and an inner value of 100 build 10,000 clones.

Once the form is submitted, each cloned field's constraints scan the whole element tree in findfieldvalue, so cost grows faster than linearly with the count. A single request exhausts memory and CPU.

The latest release on CPAN is 2.07, from 2018. Version 2.08 exists only in the git repository.

Affected Software

1 affected component
HTML::FormFu HTML::FormFu<=2.08

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade HTML::FormFu to a version that resolves this vulnerability.

    Fixed in 2.08
  2. Compensating control

    Block/limit unauthenticated requests that include the Repeatable element counter_name query-string parameter(s), since the repeat count is read on every request (including plain GET) before the form decides whether it was submitted.

Event History

Aug 31, 2026
CVE Published
via MITRE·10:07 AM
Data Sourced
via MITRE·10:07 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated attacks?

Any application using a Repeatable element with counter_name set is exposed if an attacker can send requests to the form endpoint. A plain GET request can trigger processing before submission checks, without credentials, a session, or a request body.

2

How can nested Repeatable elements affect impact?

Nested Repeatable elements multiply the number of cloned child subtrees. For example, outer and inner repeat counts of 100 result in 10,000 clones, increasing memory and CPU consumption substantially.

3

Is there an application-level setting to limit the repeat count?

No. The affected behavior validates only that the query-string value is a positive integer, and no attribute is available for an application to impose a maximum.

4

How can I identify potentially affected forms?

Review forms for Repeatable elements that have counter_name configured, including nested Repeatable elements. These forms read the named query-string parameter on every request and pass its value into the repeat operation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203