Back

HIGH

Plack::Middleware::Session versions before 0.17 for Perl may be vulnerable to HMAC comparison timing attacks

Published Dec 9, 2025

Description

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

Affected products

Remediation

Vendor solution

Upgrade to version 0.17 or higher

Red Hat statement

This vulnerability is rated Important for Red Hat products that use Plack::Middleware::Session. A timing attack on HMAC comparison could allow an attacker to infer sensitive information, potentially leading to session hijacking. Successful exploitation requires the ability to accurately measure response times, which may be challenging in typical network environments.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Dec 9, 2025
Updated Dec 11, 2025
Reserved Jul 10, 2025
CISA Vulnrichment
Updated Dec 9, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 9, 2025