Critical 9.1
CVE-2022-4993
Perl Form Handler Vulnerability with PoC Development
Vendor / product: HTML-FormHandler
Event date: 2026-06-22
Public PoC: Yes
First tracked by RiskWire: 2026-08-13
Sources & citations (2)
- CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template seclists.org · 2026-08-13
- CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template seclists.org · 2026-08-13
References
See CVE-2022-4993 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →