Critical Denial of Service Vulnerability in Fedora's perl-XML-Bare

Critical Denial of Service Vulnerability in Fedora's perl-XML-Bare

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

Fedora has released critical updates for the perl-XML-Bare module, addressing vulnerabilities that could lead to Denial of Service (DoS) and infinite loops when parsing malformed XML attributes. The vulnerabilities are identified as CVE-2026-57074 and CVE-2026-13401, both published on July 16, 2026. Affected versions are perl-XML-Bare versions up to 0.53. The updates were made available on August 30, 2026, and users are urged to apply the patches using the 'dnf' update program. The vulnerabilities could be exploited through crafted XML input, potentially affecting systems relying on this parser. The patches are crucial for maintaining system security and preventing service disruptions.

Key Points: • Critical vulnerabilities in perl-XML-Bare affect versions up to 0.53. • CVE-2026-57074 and CVE-2026-13401 can lead to Denial of Service and infinite loops. • Patches are available and should be applied immediately using the 'dnf' update program.

Ask AI about this cluster

Timeline

2026-07-16
CVE-2026-13401 published
CVE-2026-13401 was published, detailing a Denial of Service vulnerability in perl-XML-Bare.
Linuxsecurity
2026-07-16
CVE-2026-57074 published
CVE-2026-57074 was published, describing an out-of-bounds read vulnerability in perl-XML-Bare.
Linuxsecurity
2026-08-30
Security updates released
Fedora released updates for perl-XML-Bare to address CVE-2026-57074 and CVE-2026-13401.
Linuxsecurity
2026-09-08
Current status
As of today, users are advised to apply the latest patches to mitigate the vulnerabilities.
Linuxsecurity