oss-sec mailing list archives

CVE-2026-5091: Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks


From: Robert Rothenberg <rrwo () cpansec org>
Date: Thu, 21 May 2026 22:08:15 +0100

========================================================================
CVE-2026-5091                                        CPAN Security Group
========================================================================

        CVE ID:  CVE-2026-5091
  Distribution:  Catalyst-Plugin-Authentication
      Versions:  through 0.10024

      MetaCPAN: https://metacpan.org/dist/Catalyst-Plugin-Authentication
      VCS Repo: https://github.com/perl-catalyst/Catalyst-Plugin-Authentication


Catalyst::Plugin::Authentication versions through 0.10024 for Perl is
susceptible to timing attacks

Description
-----------
Catalyst::Plugin::Authentication versions through 0.10024 for Perl  is
susceptible to timing attacks.

These versions use Perl's built-in eq comparison. Discrepencies in
timing could be used to guess the underlying hash or password.

Problem types
-------------
- CWE-208 Observable Timing Discrepancy

Solutions
---------
Upgrade to version 0.10026 or later.


References
----------
https://metacpan.org/release/ETHER/Catalyst-Plugin-Authentication-0.10_025/changes
https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b0515f492257438cf07082acf1e10d06e8088a5e.patch




Current thread: