{"id":"UBUNTU-CVE-2026-5090","details":"Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected.  For example, the variable \"var\" in     \u003ca id='ref' title='[% var | html %]'\u003e would not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example,     var = \" ' onclick='while (true) { alert(1) }'\" Note that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped.","modified":"2026-06-03T22:08:51.518858499Z","published":"2026-05-19T22:16:00Z","related":["USN-8377-1"],"upstream":["CVE-2026-5090"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-5090"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-5090"},{"type":"REPORT","url":"https://lists.security.metacpan.org/cve-announce/msg/40218729/"},{"type":"REPORT","url":"https://github.com/abw/Template2/issues/327"},{"type":"REPORT","url":"https://github.com/cpan-authors/Template2/pull/337"},{"type":"REPORT","url":"https://github.com/abw/Template2/pull/337/changes/11c78a7a771d4af505efeb754a0b8775689c2eae"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2026/05/19/40"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8377-1"}],"affected":[{"package":{"name":"libtemplate-perl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libtemplate-perl?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.24-1.2build1","2.24-1.2build2"],"ecosystem_specific":{"binaries":[{"binary_version":"2.24-1.2build2","binary_name":"libtemplate-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5090.json"}},{"package":{"name":"libtemplate-perl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libtemplate-perl?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.24-1.2build5","2.27-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libtemplate-perl","binary_version":"2.27-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5090.json"}},{"package":{"name":"libtemplate-perl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libtemplate-perl?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.27-1build1","2.27-1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"libtemplate-perl","binary_version":"2.27-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5090.json"}},{"package":{"name":"libtemplate-perl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libtemplate-perl?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-1ubuntu0.22.04.1"}]}],"versions":["2.27-1build4","2.27-1build5"],"ecosystem_specific":{"binaries":[{"binary_version":"2.27-1ubuntu0.22.04.1","binary_name":"libtemplate-perl"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5090.json"}},{"package":{"name":"libtemplate-perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libtemplate-perl?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-1ubuntu0.24.04.1"}]}],"versions":["2.27-1build7","2.27-1build8","2.27-1build9","2.27-1build10"],"ecosystem_specific":{"binaries":[{"binary_version":"2.27-1ubuntu0.24.04.1","binary_name":"libtemplate-perl"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5090.json"}},{"package":{"name":"libtemplate-perl","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libtemplate-perl?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-1ubuntu0.25.10.1"}]}],"versions":["2.27-1build11"],"ecosystem_specific":{"binaries":[{"binary_version":"2.27-1ubuntu0.25.10.1","binary_name":"libtemplate-perl"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5090.json"}},{"package":{"name":"libtemplate-perl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libtemplate-perl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.102-1ubuntu0.1"}]}],"versions":["2.27-1build11","3.102-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libtemplate-perl","binary_version":"3.102-1ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5090.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}