Back

CRITICAL

Apache::Session versions through 1.94 for Perl re-creates deleted sessions

Published May 8, 2026

Description

Apache::Session versions through 1.94 for Perl re-creates deleted sessions.

The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

Affected products

Remediation

Vendor solution

Use a database store based on Apache::Session::Store::DBI.

Red Hat statement

Low impact. This flaw in the Apache::Session Perl module allows for the re-creation of previously deleted sessions. While this primarily affects data integrity by reviving old session records, it does not directly lead to data leakage or modification. Exploitation for authentication bypass is application-dependent and not a direct consequence of the flaw itself.

Red Hat mitigation

The vulnerable session store backends (Apache::Session::Store::File and Apache::Session::Store::DB_File) can be replaced with a DBI-based backend such as Apache::Session::Store::DBI, Apache::Session::Store::MySQL, or Apache::Session::Store::Postgres, which are not affected by this flaw. Applications using Apache::Session::Flex can change the Store parameter without other code changes. As an additional defense, applications should validate session contents (e.g. authentication tokens or user attributes) rather than treating session existence alone as proof of authentication.

Metrics

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published May 8, 2026
Updated May 8, 2026
Reserved Apr 20, 2026
CISA Vulnrichment
Updated May 8, 2026
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 8, 2026