Back

CRITICAL

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()

Published May 27, 2026

Description

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().

send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append.

Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.

Affected products

Remediation

Vendor solution

Upgrade to HTTP-Daemon 6.17 or later.

Red Hat statement

This is rated as an Important security flaw becaye the function utilizes an insecure 2-argument open() call that interprets shell-magic characters (such as pipes or redirects) inside file paths. In a non-default configuration where a custom application passes untrusted user input directly to this function, a remote attacker could exploit this flaw to read or write arbitrary files, or potentially execute commands within the context of the daemon's local system user.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published May 27, 2026
Updated Jul 15, 2026
Reserved May 12, 2026
CISA Vulnrichment
Updated May 27, 2026
NVD
Status Deferred
Modified Jul 23, 2026
Red Hat
Severity Important
Public date May 27, 2026
ENISA EUVD
Assigner CPANSec
Published May 27, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-32050