CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-19872: HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6777

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-19872: HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message

CVE-2026-19872 affects HTML::FormHandler for Perl versions before 0.410000, allowing cross-site scripting (XSS) when user-submitted values are rendered unescaped in error messages. The vulnerability was disclosed by the CPAN Security Group on September 8, 2026.

Why it matters: Perl developers and system administrators using HTML::FormHandler must upgrade to version 0.410000 or later to prevent XSS attacks that could expose user sessions or inject malicious content through form error messages.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary