{"id":"CVE-2026-85485","summary":"HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping","details":"HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping.\n\nThe Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escaped the equivalent values in the other layouts and wrappers, and 0.410002 extended that to these three.\n\nError messages that contain attacker-influenced content such as rejected field values could embed JavaScript in rendered pages.","modified":"2026-09-12T03:47:19.870621494Z","published":"2026-09-08T20:09:08.909Z","related":["openSUSE-SU-2026:11745-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85485.json","cna_assigner":"CPANSec","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85485.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/ABRAXXA/HTML-FormHandler-0.410002/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85485"},{"type":"FIX","url":"https://github.com/gshank/html-formhandler/commit/2ea9e138dbfe231e317c13936abe6583217c807f.patch"},{"type":"PACKAGE","url":"https://github.com/gshank/html-formhandler"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gshank/html-formhandler","events":[{"introduced":"0"},{"fixed":"95ee0beae6be208c4efc80fc72a7f4992015e731"},{"fixed":"2ea9e138dbfe231e317c13936abe6583217c807f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.410002"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["0.410001","0.410000","0.40068","0.40067","0.40066","0.40065","0.40064","0.40063","0.40062","0.40061","0.40060","0.40059","0.40058","0.40057","0.40056","0.40055","0.40054","0.40053","0.40052","0.40051","0.40050","0.40028","0.40027","0.40026","0.40025","0.40024","0.40023","0.40022","0.40021","0.40020","0.40019","0.40018","0.40017","0.40016","0.40015","0.40014","0.40013","0.40012","0.40011","0.40010","0.40009","0.40008","0.40007","0.40006","0.40005","0.40004","0.40003","0.40002","0.40001","0.40000","0.36001","0.36000","0.35005","0.35003","0.35002","0.35001","0.35000","0.34001","0.34000","0.33002","0.33001","0.31003","0.27003","0.27002","0.27","0.23","0.22","ver-0.20","ver17+","ver15","roles","ver13","ver12","ver10","inherit_has_fields","dup_fields_order","ver09","has_field","ver08","after-persist","empty-row"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85485.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}