CVE-2026-19873
Received Received - Intake

Resource Exhaustion in HTML::FormFu Perl Module

Vulnerability report for CVE-2026-19873, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: CPANSec

Description

HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer, and passes it to repeat, which deep-clones the element's child subtree once per iteration. Nothing caps the value, and no attribute lets an application impose a limit. The count is read on every request, before the form decides whether it was submitted, so a plain GET reaches the clone loop with no credentials, no session and no request body. Nesting multiplies: a Repeatable inside a Repeatable takes a counter at each level, so an outer and an inner value of 100 build 10,000 clones. Once the form is submitted, each cloned field's constraints scan the whole element tree in _find_field_value, so cost grows faster than linearly with the count. A single request exhausts memory and CPU. The latest release on CPAN is 2.07, from 2018. Version 2.08 exists only in the git repository.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
formfu html-formfu to 2.08 (exc)
formfu html_formfu to 2.08 (exc)
formfu html-formfu to 2.08 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in HTML::FormFu for Perl allows attackers to cause CPU and memory exhaustion by sending a query string with an unbounded repeat count. The Repeatable element's counter_name feature reads the repeat count directly from the query string without any upper limit. It validates only that the value is a positive integer, then deep-clones the element's child subtree once per iteration. This can be triggered via a simple GET request without authentication or session.

Detection Guidance

Check for unusually high CPU or memory usage during web requests. Monitor for GET requests with large repeat count parameters like outer_count and inner_count in URLs. Inspect logs for repeated form submissions with high repeat values.

Impact Analysis

An attacker could exploit this to consume excessive CPU and memory on your server with a single request. This may lead to service outages, slow response times, or system crashes. The impact is worse with nested Repeatable elements, as the resource usage multiplies exponentially. Even small values like 100 can create thousands of cloned fields, rapidly exhausting resources.

Compliance Impact

This vulnerability could lead to service unavailability, which may violate availability requirements in GDPR and HIPAA. Downtime could result in unauthorized access to data during outages or failure to provide timely access to personal health information under HIPAA. It may also indicate poor security practices, potentially affecting compliance with data protection and security controls.

Mitigation Strategies

Upgrade to a patched version of HTML-FormFu if available. Implement server-side input validation to cap repeat count values. Disable Repeatable elements with counter_name if not needed. Use rate limiting to prevent excessive requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19873. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart