Back

CRITICAL

HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids

Published Mar 28, 2026

Description

HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids.

HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the high resolution epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.

The distribution includes HTTP::session::ID::MD5 which contains a similar flaw, but uses the MD5 hash instead.

Affected products

Remediation

Vendor solution

Upgrade to version 0.54 or later.

Note that HTTP::Session as of version 0.54 is deprecated. Users should migrate their applications to alternative solutions.

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Mar 28, 2026
Updated Jun 29, 2026
Reserved Feb 26, 2026
CISA Vulnrichment
Updated Apr 1, 2026
NVD
Status Modified
Modified Jun 29, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CPANSec
Published Mar 28, 2026
Updated Jun 29, 2026
Exploited since n/a
EUVD-2026-16939