{"id":"CVE-2026-19873","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-19873","summary":"HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements.\n\nWhen a Repeatable element has counter_name…","details":"HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements.\n\nWhen a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer, and passes it to repeat, which deep-clones the element's child subtree once per iteration. Nothing caps the value, and no attribute lets an application impose a limit.\n\nThe count is read on every request, before the form decides whether it was submitted, so a plain GET reaches the clone loop with no credentials, no session and no request body. Nesting multiplies: a Repeatable inside a Repeatable takes a counter at each level, so an outer and an inner value of 100 build 10,000 clones.\n\nOnce the form is submitted, each cloned field's constraints scan the whole element tree in _find_field_value, so cost grows faster than linearly with the count. A single request exhausts memory and CPU.\n\nThe latest release on CPAN is 2.07, from 2018. Version 2.08 exists only in the git repository.","published":"2026-08-31T10:16:49.790","modified":"2026-08-31T10:16:49.790","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FormFu/HTML-FormFu/issues/71"},{"type":"WEB","url":"https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-31T10:16:49.790"}}