CVE-2026-8829
It was discovered that HTML-Parser incorrectly handled entity references when the input string was identical to an entity value in the lookup table. An attacker could possibly use this issue to obtain sensitive information.
CSIRTS triage
- What
- HTML-Parser incorrectly handled entity references, potentially allowing sensitive information to be obtained.
- Who is affected
- Users of HTML-Parser that process input strings identical to entity values.
- Urgency
- Remediation is necessary due to the potential for information disclosure.
- Action
- Update to the latest version of HTML-Parser.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-8829
Get an email if CVE-2026-8829 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownUSN-8587-1: HTML-Parser vulnerabilityubuntu · 2026-07-22
- highCVE-2026-8829: HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entitiesmsrc · 2026-06-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-8829)