CVE-2026-8829: HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities
Published Jun 4, 2026
·Updated
HTML::Entities versions before 3.84 for Perl read freed heap memory in decodeentities
Affected Software
7 affected componentsFixes available
cpan/HTML::Entities<3.84
Microsoft azl3 perl-HTML-Parser 3.82-1<3.82-2
3.82-2
debian/libhtml-parser-perl<=3.75-1
3.75-1+deb11u13.81-1+deb12u13.83-2~deb13u13.83-2
Oalders Html\<3.84
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.82-2 - Upgrade
Upgrade
debian/libhtml-parser-perlto a version that resolves this vulnerability.Fixed in 3.75-1+deb11u1Fixed in 3.81-1+deb12u1Fixed in 3.83-2~deb13u1Fixed in 3.83-2 - Upgrade
Upgrade
Perl HTML::Entitiesto a version that resolves this vulnerability.Fixed in 3.84
Event History
Jun 4, 2026
CVE Published
via MITRE·02:03 AM
Data Sourced
via MITRE·02:03 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 7, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Jul 22, 2026
Data Sourced
via Ubuntu·03:17 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:18 PM
DescriptionAffected Software
Data Sourced
via Launchpad·03:18 PM
Description
Aug 15, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-8829?
The severity of CVE-2026-8829 is high with a CVSS score of 7.5.
2
What does CVE-2026-8829 affect?
CVE-2026-8829 affects HTML::Entities versions before 3.84 for Perl.
3
What kind of vulnerability is CVE-2026-8829?
CVE-2026-8829 is classified as a Use After Free vulnerability.
4
How do I fix CVE-2026-8829?
To fix CVE-2026-8829, upgrade to HTML-Parser version 3.84 or later.
5
What specific function is vulnerable in CVE-2026-8829?
The vulnerable function in CVE-2026-8829 is _decode_entities within HTML::Entities.