Back

CRITICAL

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack

Published Mar 19, 2026

Description

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.

In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer.

The bug can be observed when parsing an XML file with very deep element nesting

Affected products

Remediation

Vendor solution

Apply the patch that has been publicly available since 2006-06-13 or upgrade to version 2.48 or later when it is released.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (2)

References (24)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CPANSec
Published Mar 19, 2026
Updated Jul 15, 2026
Reserved Mar 16, 2026

CISA Vulnrichment

Updated Mar 19, 2026

NVD

Status Modified
Modified Jul 15, 2026

Red Hat

Severity Important
Public date Mar 19, 2026
Bugzilla 2448999

ENISA EUVD

Assigner CPANSec
Published Mar 19, 2026
Updated Jul 15, 2026

GitHub

No data