Bug 2530105 (CVE-2026-19872) - CVE-2026-19872 perl-HTML-FormHandler: HTML::FormHandler: Cross-site scripting via unescaped error messages
Summary: CVE-2026-19872 perl-HTML-FormHandler: HTML::FormHandler: Cross-site scripting...
Keywords:
Status: NEW
Alias: CVE-2026-19872
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2533273
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-08 20:25 UTC by OSIDB Bzimport
Modified: 2026-09-14 18:18 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-08 20:25:11 UTC
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message.

The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and not_allowed, splice the submitted value into that string, and a failing type constraint puts the rejected value into the message it builds, which _apply_actions hands to add_error.

A field declared with a check regexp, a check list or a type constraint reaches those messages, with no custom validator and no non-default configuration. Errors rendered through an application's own escaping template layer rather than the library's rendering roles are not affected.

A request over the network that submits markup to such a field gets it back live inside the error span, running script in the victim's origin. Re-rendering a rejected value later gives the stored variant.


Note You need to log in before you can comment on or make changes to this bug.