CVE-2026-85484: medium-severity vulnerability in HTML-FormHandler
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.1epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping.
The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also renders each radio button's own label unescaped.
Any application whose option list is built from data rather than literals, using options_from, an options_fieldname method, or the DBIC model, allows attacker-influenced text in a label that can override the options or embed JavaScript in rendered pages.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
HTML-FormHandlerRelated CVEs — HTML-FormHandler
In the same product, most dangerous first.
CVE-2022-4993CRITICALHTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation templateEPSS 0.6%CVE-2026-85485MEDIUMHTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escapingEPSS 0.3%CVE-2026-19872MEDIUMHTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error messageEPSS 0.3%CVE-2026-85630MEDIUMHTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs methodEPSS 0.2%