{"id":"CVE-2026-19872","summary":"HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message","details":"HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message.\n\nThe wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and not_allowed, splice the submitted value into that string, and a failing type constraint puts the rejected value into the message it builds, which _apply_actions hands to add_error.\n\nA field declared with a check regexp, a check list or a type constraint reaches those messages, with no custom validator and no non-default configuration. Errors rendered through an application's own escaping template layer rather than the library's rendering roles are not affected.\n\nA request over the network that submits markup to such a field gets it back live inside the error span, running script in the victim's origin. Re-rendering a rejected value later gives the stored variant.","modified":"2026-09-12T03:30:25.844780979Z","published":"2026-09-08T20:08:21.896Z","related":["openSUSE-SU-2026:11745-1"],"database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19872.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/08/15"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19872.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/ABRAXXA/HTML-FormHandler-0.410000/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19872"},{"type":"FIX","url":"https://github.com/gshank/html-formhandler/commit/2574fdb4561f5c32d44cfbfbb3188345d49eb5a2.patch"},{"type":"PACKAGE","url":"https://github.com/gshank/html-formhandler"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gshank/html-formhandler","events":[{"introduced":"0"},{"fixed":"4aa24166e3a5cdbc3b64aa8a63c9d4ca8c529f34"},{"fixed":"2574fdb4561f5c32d44cfbfbb3188345d49eb5a2"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.410000"}]}}],"versions":["0.40068","0.40067","0.40066","0.40065","0.40064","0.40063","0.40062","0.40061","0.40060","0.40059","0.40058","0.40057","0.40056","0.40055","0.40054","0.40053","0.40052","0.40051","0.40050","0.40028","0.40027","0.40026","0.40025","0.40024","0.40023","0.40022","0.40021","0.40020","0.40019","0.40018","0.40017","0.40016","0.40015","0.40014","0.40013","0.40012","0.40011","0.40010","0.40009","0.40008","0.40007","0.40006","0.40005","0.40004","0.40003","0.40002","0.40001","0.40000","0.36001","0.36000","0.35005","0.35003","0.35002","0.35001","0.35000","0.34001","0.34000","0.33002","0.33001","0.31003","0.27003","0.27002","0.27","0.23","0.22","ver-0.20","ver17+","ver15","roles","ver13","ver12","ver10","inherit_has_fields","dup_fields_order","ver09","has_field","ver08","after-persist","empty-row"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19872.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}