Skip to content
Fedora 43 perl-HTML-Gumbo Important Memory Disclosure Vuln 2026

Fedora 43 perl-HTML-Gumbo Important Memory Disclosure Vuln 2026

Linuxsecurity •LinuxSecurity Advisories • July 11, 2026

This package provides the Perl module HTML::Gumbo. Versions before 0.19 disclose heap memory via type confusion. Support for the element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses.

* Sat May 30 2026 Emmanuel Seyman - 0.19-1 - Update to 0.19 - Update dependencies - Use /usr/bin/perl instead of %{__perl}

* Sat May 30 2026 Emmanuel Seyman - 0.19-1 - Update to 0.19 - Update dependencies - Use /usr/bin/perl instead of %{__perl}

[ 1 ] Bug #2496536 - CVE-2025-15646 perl-HTML-Gumbo: HTML::Gumbo: Information disclosure through HTML template processing [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a457bf78b4' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)