Security Advisories (1)
CVE-2026-19873 (2026-08-31)

HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer, and passes it to repeat, which deep-clones the element's child subtree once per iteration. Nothing caps the value, and no attribute lets an application impose a limit. The count is read on every request, before the form decides whether it was submitted, so a plain GET reaches the clone loop with no credentials, no session and no request body. Nesting multiplies: a Repeatable inside a Repeatable takes a counter at each level, so an outer and an inner value of 100 build 10,000 clones. Once the form is submitted, each cloned field's constraints scan the whole element tree in _find_field_value, so cost grows faster than linearly with the count. A single request exhausts memory and CPU. The latest release on CPAN is 2.07, from 2018. Version 2.08 exists only in the git repository.

NAME

HTML::FormFu::Element::Block - Block element

VERSION

version 2.07

SYNOPSIS

---
elements:
  - type: Block
    elements:
      - type: Text
        name: foo

  - type: Block
    tag: span
    content: Whatever

DESCRIPTION

Block element which may contain other elements.

METHODS

tag

Specifies which tag name should be used to render the block.

Default Value: 'div'

content

If "content" is set, it is used as the block's contents, and any attached elements are ignored.

content_xml

Arguments: $string

If you don't want the content to be XML-escaped, use the "content_xml" method instead of "content".

content_loc

Arguments: $localization_key

To set the content to a localized string, set "content_loc" to a key in your L10N file instead of using "content".

elements

See "elements" in HTML::FormFu for details.

element

See "element" in HTML::FormFu for details.

deflators

See "deflators" in HTML::FormFu for details.

deflator

See "deflator" in HTML::FormFu for details.

filters

See "filters" in HTML::FormFu for details.

filter

See "filter" in HTML::FormFu for details.

constraints

See "constraints" in HTML::FormFu for details.

constraint

See "constraint" in HTML::FormFu for details.

inflators

See "inflators" in HTML::FormFu for details.

inflator

See "inflator" in HTML::FormFu for details.

validators

See "validators" in HTML::FormFu for details.

validator

See "validator" in HTML::FormFu for details.

transformers

See "transformers" in HTML::FormFu for details.

transformer

See "transformer" in HTML::FormFu for details.

auto_datalist_id

See "auto_datalist_id" in HTML::FormFu for details.

CSS CLASSES

auto_id

See "auto_id" in HTML::FormFu for details.

auto_block_id

Arguments: [$string]

If set, the Block will be given an auto-generated id attribute, if it doesn't have one already.

The following character substitution will be performed: %f will be replaced by $form->id, %r will be replaced by $block->repeatable_count.

Default Value: not defined

Unlike most other auto_* methods, this is not an 'inherited accessor'.

auto_label

See "auto_label" in HTML::FormFu for details.

auto_error_field_class

See "auto_error_field_class" in HTML::FormFu for details.

auto_error_class

See "auto_error_class" in HTML::FormFu for details.

auto_error_message

See "auto_error_message" in HTML::FormFu for details.

auto_constraint_class

See "auto_constraint_class" in HTML::FormFu for details.

auto_inflator_class

See "auto_inflator_class" in HTML::FormFu for details.

auto_validator_class

See "auto_validator_class" in HTML::FormFu for details.

auto_transformer_class

See "auto_transformer_class" in HTML::FormFu for details.

default_args

See "default_args" in HTML::FormFu for details.

RENDERING

start

end

INTROSPECTION

get_elements

See "get_elements" in HTML::FormFu for details.

get_element

See "get_element" in HTML::FormFu for details.

get_all_elements

See "get_all_elements" in HTML::FormFu for details.

get_fields

See "get_fields" in HTML::FormFu for details.

get_field

See "get_field" in HTML::FormFu for details.

get_deflators

See "get_deflators" in HTML::FormFu for details.

get_deflator

See "get_deflator" in HTML::FormFu for details.

get_filters

See "get_filters" in HTML::FormFu for details.

get_filter

See "get_filter" in HTML::FormFu for details.

get_constraints

See "get_constraints" in HTML::FormFu for details.

get_constraint

See "get_constraint" in HTML::FormFu for details.

get_inflators

See "get_inflators" in HTML::FormFu for details.

get_inflator

See "get_inflator" in HTML::FormFu for details.

get_validators

See "get_validators" in HTML::FormFu for details.

get_validator

See "get_validator" in HTML::FormFu for details.

get_transformers

See "get_transformers" in HTML::FormFu for details.

get_transformer

See "get_transformer" in HTML::FormFu for details.

get_errors

See "get_errors" in HTML::FormFu for details.

clear_errors

See "clear_errors" in HTML::FormFu for details.

SEE ALSO

Base-class for HTML::FormFu::Element::Fieldset.

Is a sub-class of, and inherits methods from HTML::FormFu::Element

HTML::FormFu

REMOVED METHODS

element_defaults

Has been removed; use "default_args" instead.

AUTHOR

Carl Franks, cfranks@cpan.org

LICENSE

This library is free software, you can redistribute it and/or modify it under the same terms as Perl itself.

AUTHOR

Carl Franks <cpan@fireartist.com>

COPYRIGHT AND LICENSE

This software is copyright (c) 2018 by Carl Franks.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.