Back

HIGH

Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths

Published May 28, 2026

Description

Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths.

The header injection rule was ineffective at blocking header injections in the request paths unless they were double-encoded, for example,

GET /path\r\nHTTP/1.1\r\nHost: secret.example.com

Note that it is unclear whether request paths with CRLF followed by additional headers would be blocked by reverse proxies, or how they would be processed by Plack-based servers.

Affected products

Remediation

Vendor solution

Upgrade to 0.13.1 or later.

Weaknesses (2)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published May 28, 2026
Updated Jun 1, 2026
Reserved May 26, 2026
CISA Vulnrichment
Updated Jun 1, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a