HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids
Published Mar 28, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.71%
Description
HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids.
HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the high resolution epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.
The distribution includes HTTP::session::ID::MD5 which contains a similar flaw, but uses the MD5 hash instead.
Affected products
-
- Version 0StatusaffectedConstraints<0.54
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| KTAT | n/a | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 0.54 or later.
Note that HTTP::Session as of version 0.54 is deprecated. Users should migrate their applications to alternative solutions.
References (6)
- http://www.openwall.com/lists/oss-security/2026/03/28/5 Mailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16939 Advisory
- https://metacpan.org/release/KTAT/http-session-0.53/source/lib/HTTP/Session/ID/MD5.pm Product
- https://metacpan.org/release/KTAT/http-session-0.53/source/lib/HTTP/Session/ID/SHA1.pm Product
- https://metacpan.org/release/TOKUHIROM/http-session-0.54/changes release-notes
- https://security.metacpan.org/docs/guides/random-data-for-security.html technical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/03/28/5 | Mailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16939 | Advisory | |
| https://metacpan.org/release/KTAT/http-session-0.53/source/lib/HTTP/Session/ID/MD5.pm | Product | |
| https://metacpan.org/release/KTAT/http-session-0.53/source/lib/HTTP/Session/ID/SHA1.pm | Product | |
| https://metacpan.org/release/TOKUHIROM/http-session-0.54/changes | release-notes | |
| https://security.metacpan.org/docs/guides/random-data-for-security.html | technical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.