Skip to content
Fedora 44 perl-HTML-Gumbo Critical Information Disclosure 2026

Fedora 44 perl-HTML-Gumbo Critical Information Disclosure 2026

Linuxsecurity •LinuxSecurity Advisories • July 11, 2026

This package provides the Perl module HTML::Gumbo. Versions before 0.19 disclose heap memory via type confusion. Support for the element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses.

* Sat May 30 2026 Emmanuel Seyman - 0.19-1 - Update to 0.19 - Update dependencies - Use /usr/bin/perl instead of %{__perl}

* Sat May 30 2026 Emmanuel Seyman - 0.19-1 - Update to 0.19 - Update dependencies - Use /usr/bin/perl instead of %{__perl}

[ 1 ] Bug #2496536 - CVE-2025-15646 perl-HTML-Gumbo: HTML::Gumbo: Information disclosure through HTML template processing [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-75010c7f44' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.