oss-sec mailing list archives
CVE-2026-5091: Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks
From: Robert Rothenberg <rrwo () cpansec org>
Date: Thu, 21 May 2026 22:08:15 +0100
======================================================================== CVE-2026-5091 CPAN Security Group ======================================================================== CVE ID: CVE-2026-5091 Distribution: Catalyst-Plugin-Authentication Versions: through 0.10024 MetaCPAN: https://metacpan.org/dist/Catalyst-Plugin-AuthenticationVCS Repo: https://github.com/perl-catalyst/Catalyst-Plugin-Authentication
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks Description ----------- Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Problem types ------------- - CWE-208 Observable Timing Discrepancy Solutions --------- Upgrade to version 0.10026 or later. References ---------- https://metacpan.org/release/ETHER/Catalyst-Plugin-Authentication-0.10_025/changes https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b0515f492257438cf07082acf1e10d06e8088a5e.patch
Current thread:
- CVE-2026-5091: Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks Robert Rothenberg (May 21)
