CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-8829

highCVSS 7.5covered by 2 sourcesfirst seen 2026-06-09
It was discovered that HTML-Parser incorrectly handled entity references when the input string was identical to an entity value in the lookup table. An attacker could possibly use this issue to obtain sensitive information.

CSIRTS triage

What
HTML-Parser incorrectly handled entity references, potentially allowing sensitive information to be obtained.
Who is affected
Users of HTML-Parser that process input strings identical to entity values.
Urgency
Remediation is necessary due to the potential for information disclosure.
Action
Update to the latest version of HTML-Parser.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-8829

Get an email if CVE-2026-8829 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-8829

CVE.org record

Embed the live status

CVE-2026-8829 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-8829 status](https://www.csirts.com/badge/CVE-2026-8829)](https://www.csirts.com/cve/CVE-2026-8829)