Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5091

Опубликовано: 21 мая 2026
Источник: debian
EPSS Низкий

Описание

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcatalyst-plugin-authentication-perlfixed0.10026-1package
libcatalyst-plugin-authentication-perlno-dsatrixiepackage
libcatalyst-plugin-authentication-perlno-dsabookwormpackage
libcatalyst-plugin-authentication-perlpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/40281889/

  • https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b0515f492257438cf07082acf1e10d06e8088a5e (v0.10_025)

EPSS

Процентиль: 10%
0.00196
Низкий

Связанные уязвимости

CVSS3: 5.1
ubuntu
3 месяца назад

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

CVSS3: 5.1
nvd
3 месяца назад

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

CVSS3: 5.1
github
3 месяца назад

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

EPSS

Процентиль: 10%
0.00196
Низкий