{"id":"CVE-2026-85630","summary":"HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method","details":"HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method.\n\nAny application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the field attributes or embed JavaScript in rendered pages.\n\nFor example, the RadioGroup widget uses the process_attrs method via the render_option and wrap_radio methods.","modified":"2026-09-10T03:48:25.523498272Z","published":"2026-09-08T20:09:38.490Z","database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85630.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"0.410002"}]},{"source":"DESCRIPTION","extracted_events":[{"fixed":"0.410002"}]}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/08/18"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85630.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/ABRAXXA/HTML-FormHandler-0.410002/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85630"},{"type":"FIX","url":"https://github.com/gshank/html-formhandler/commit/a887271e91d755e6486a9f433ae932deb1d2c4a6.patch"},{"type":"PACKAGE","url":"https://github.com/gshank/html-formhandler"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gshank/html-formhandler","events":[{"introduced":"0"},{"fixed":"a887271e91d755e6486a9f433ae932deb1d2c4a6"}],"database_specific":{"source":"REFERENCES"}}],"versions":["0.410001","0.410000","0.40068","0.40067","0.40066","0.40065","0.40064","0.40063","0.40062","0.40061","0.40060","0.40059","0.40058","0.40057","0.40056","0.40055","0.40054","0.40053","0.40052","0.40051","0.40050","0.40028","0.40027","0.40026","0.40025","0.40024","0.40023","0.40022","0.40021","0.40020","0.40019","0.40018","0.40017","0.40016","0.40015","0.40014","0.40013","0.40012","0.40011","0.40010","0.40009","0.40008","0.40007","0.40006","0.40005","0.40004","0.40003","0.40002","0.40001","0.40000","0.36001","0.36000","0.35005","0.35003","0.35002","0.35001","0.35000","0.34001","0.34000","0.33002","0.33001","0.31003","0.27003","0.27002","0.27","0.23","0.22","ver-0.20","ver17+","ver15","roles","ver13","ver12","ver10","inherit_has_fields","dup_fields_order","ver09","has_field","ver08","after-persist","empty-row"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85630.json"}}],"schema_version":"1.9.0"}