Back

MEDIUM

Ado::Sessions versions through 0.935 for Perl generates insecure session ids

Published Apr 8, 2026

Description

Ado::Sessions versions through 0.935 for Perl generates insecure session ids.

The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.

Predicable session ids could allow an attacker to gain access to systems.

Note that Ado is no longer maintained, and has been removed from the CPAN index. It is still available on BackPAN.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Apr 8, 2026
Updated Apr 8, 2026
Reserved Mar 28, 2026
CISA Vulnrichment
Updated Apr 8, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a