Bug 2530115 (CVE-2026-85485) - CVE-2026-85485 perl-HTML-FormHandler: HTML::FormHandler: Cross-Site Scripting via unescaped error messages
Summary: CVE-2026-85485 perl-HTML-FormHandler: HTML::FormHandler: Cross-Site Scripting...
Keywords:
Status: NEW
Alias: CVE-2026-85485
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2533729
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-08 20:25 UTC by OSIDB Bzimport
Modified: 2026-09-15 12:34 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-08 20:25:26 UTC
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping.

The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escaped the equivalent values in the other layouts and wrappers, and 0.410002 extended that to these three.

Error messages that contain attacker-influenced content such as rejected field values could embed JavaScript in rendered pages.


Note You need to log in before you can comment on or make changes to this bug.