CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements.
When a Repeatable element has countername set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer, and passes it to repeat, which deep-clones the element's child subtree once per iteration. Nothing caps the value, and no attribute lets an application impose a limit.
The count is read on every request, before the form decides whether it was submitted, so a plain GET reaches the clone loop with no credentials, no session and no request body. Nesting multiplies: a Repeatable inside a Repeatable takes a counter at each level, so an outer and an inner value of 100 build 10,000 clones.
Once the form is submitted, each cloned field's constraints scan the whole element tree in findfieldvalue, so cost grows faster than linearly with the count. A single request exhausts memory and CPU.
The latest release on CPAN is 2.07, from 2018. Version 2.08 exists only in the git repository.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HTML::FormFuto a version that resolves this vulnerability.Fixed in 2.08 - Compensating control
Block/limit unauthenticated requests that include the Repeatable element counter_name query-string parameter(s), since the repeat count is read on every request (including plain GET) before the form decides whether it was submitted.
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated attacks?
Any application using a Repeatable element with counter_name set is exposed if an attacker can send requests to the form endpoint. A plain GET request can trigger processing before submission checks, without credentials, a session, or a request body.
How can nested Repeatable elements affect impact?
Nested Repeatable elements multiply the number of cloned child subtrees. For example, outer and inner repeat counts of 100 result in 10,000 clones, increasing memory and CPU consumption substantially.
Is there an application-level setting to limit the repeat count?
No. The affected behavior validates only that the query-string value is a positive integer, and no attribute is available for an application to impose a maximum.
How can I identify potentially affected forms?
Review forms for Repeatable elements that have counter_name configured, including nested Repeatable elements. These forms read the named query-string parameter on every request and pass its value into the repeat operation.