Back Linuxsecurity Fedora 43 perl-HTML-FormFu Denial of Service Fix Advisory 2026
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
HTML::FormFu is a HTML form framework which aims to be as easy as possible
to use for basic web forms, but with the power and flexibility to do
anything else you might want to do (as long as it involves forms).
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. In this package, a max_counter attribute has been added to Repeatable elements that caps the client-supplied repeat count from the query string. Default is 100, inherited from a new form-level repeatable_max_counter attribute.
* Sun Sep 20 2026 Emmanuel Seyman - 2.07-22 - Modernize spec file - Apply fix to CVE-2026-19873
* Sun Sep 20 2026 Emmanuel Seyman - 2.07-22 - Modernize spec file - Apply fix to CVE-2026-19873
[ 1 ] Bug #2536983 - CVE-2026-19873 perl-HTML-FormFu: HTML::FormFu: Denial of Service via unbounded repeat count in Repeatable elements [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-219b6aef6c' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
