CVE-2026-19872
Deferred Deferred - Pending Action

Cross-Site Scripting in HTML::FormHandler for Perl

Vulnerability report for CVE-2026-19872, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: CPANSec

Description

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and not_allowed, splice the submitted value into that string, and a failing type constraint puts the rejected value into the message it builds, which _apply_actions hands to add_error. A field declared with a check regexp, a check list or a type constraint reaches those messages, with no custom validator and no non-default configuration. Errors rendered through an application's own escaping template layer rather than the library's rendering roles are not affected. A request over the network that submits markup to such a field gets it back live inside the error span, running script in the victim's origin. Re-rendering a rejected value later gives the stored variant.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Scripting (XSS) issue in the HTML::FormHandler Perl module versions before 0.410000. Error messages were not properly HTML-escaped before being rendered, allowing malicious scripts to be injected via user input. The problem occurs when error messages like no_match and not_allowed directly interpolate submitted values into HTML without sanitization.

Detection Guidance

To detect this vulnerability, inspect Perl applications using HTML::FormHandler versions before 0.410000 for improper HTML escaping in error messages. Check if error messages from fields with check regexp, check list, or type constraints render user input without escaping. Use commands like grep -r 'HTML::FormHandler' /path/to/app to locate affected modules and review error message handling in code.

Impact Analysis

An attacker could submit malicious markup in a form field, which would then execute in the victim's browser when the error message is displayed. This could lead to theft of session cookies, account takeover, or other malicious actions. The stored variant of the rejected value can also trigger the issue upon re-rendering.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Failure to address XSS risks may result in non-compliance with these regulations, potentially leading to legal penalties and reputational damage.

Mitigation Strategies

Immediately upgrade HTML::FormHandler to version 0.410000 or later. Review and update custom error message templates to ensure proper HTML escaping. Audit all form fields using check regexp, check list, or type constraints for potential XSS vectors. Apply the official patch from the GitHub commit if upgrading is not immediately feasible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19872. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart