A flaw tracked as CVE-2025-15646 was fixed in HTML-Gumbo / Debian's libhtml-gumbo-perl after incorrect handling of the HTML <template> element caused erratic behavior and use of uninitialized memory during string output generation. The bug affected the GUMBO_NODE_TEMPLATE node type, which had been introduced in Gumbo 0.10.0 but was not properly supported by the Perl bindings, leading the parser to treat template nodes as text nodes and produce random output alongside Valgrind warnings in Gumbo.xs.
A patch updated walk_tree() so GUMBO_NODE_TEMPLATE is processed like document and element container nodes instead of following the text-node code path. The fix attaches a GumboElement value rather than a GumboText, addressing the memory-handling issue reported in Debian Bug #1104789 and GitHub issue #6. Debian shipped the remediation in libhtml-gumbo-perl version 0.18-5, while noting that full <template> support remains a separate enhancement topic.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Debian Bug #1104789 documented CVE-2025-15646 in libhtml-gumbo-perl, where parsing the HTML <template> element could cause erratic behavior and use of uninitialized memory during string output generation. Debian noted the issue was fixed in libhtml-gumbo-perl version 0.18-5.
A patch was submitted for HTML-Gumbo to correct handling of the GUMBO_NODE_TEMPLATE node type, which had been incorrectly processed as a text node and could access uninitialized memory. The fix changes walk_tree() so template nodes are treated as container nodes and assigned a GumboElement value.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.