A heap memory disclosure flaw tracked as CVE-2025-15646 was disclosed in HTML::Gumbo for Perl, affecting versions before 0.19. The bug is caused by type confusion in the walk_tree function after libgumbo added support for the HTML <template> element, leading the code to mis-handle that element as a text node and causing strlen() to over-read heap memory.
When applications call parse() with the default format => 'string' setting, or with format => 'tree', and process input containing a <template> element, bounded heap contents can be serialized into the returned result and exposed. The issue was fixed in HTML-Gumbo 0.19 by adding GUMBO_NODE_TEMPLATE to the container node types handled by walk_tree.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
HTML::Gumbo version 0.19 fixed an information disclosure vulnerability affecting earlier versions, where type confusion in walk_tree could cause strlen() to over-read heap memory when parsing input containing a <template> element. The fix added GUMBO_NODE_TEMPLATE to the container node types handled by walk_tree.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceseclists.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.