CVE-2025-15646

NameCVE-2025-15646
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1104789

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libhtml-gumbo-perl (PTS)bullseye0.18-2vulnerable
bookworm0.18-3vulnerable
forky, trixie0.18-5fixed
sid0.19-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libhtml-gumbo-perlsource(unstable)0.18-51104789

Notes

[bookworm] - libhtml-gumbo-perl <no-dsa> (Minor issue; to be fixed in point release)
https://github.com/ruz/HTML-Gumbo/issues/6
https://github.com/bestpractical/html-gumbo/commit/15c0598909d4a64f47ef0a1abc5051f4e113c186 (0.19)

Search for package or bug name: Reporting problems