Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8450

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.

A flaw was found in HTTP::Daemon, a Perl module used for creating HTTP servers. A remote attacker can exploit this vulnerability by providing specially crafted input to the send_file() function, leading to OS command injection. This allows the attacker to execute arbitrary commands on the system with the privileges of the daemon process, potentially resulting in full system compromise or data manipulation.

Отчет

This is rated as an Important security flaw becaye the function utilizes an insecure 2-argument open() call that interprets shell-magic characters (such as pipes or redirects) inside file paths. In a non-default configuration where a custom application passes untrusted user input directly to this function, a remote attacker could exploit this flaw to read or write arbitrary files, or potentially execute commands within the context of the daemon's local system user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7perl-HTTP-DaemonAffected
Red Hat Enterprise Linux 10perl-HTTP-DaemonFixedRHSA-2026:3618907.07.2026
Red Hat Enterprise Linux 8perl-HTTP-DaemonFixedRHSA-2026:3618807.07.2026
Red Hat Enterprise Linux 9perl-HTTP-DaemonFixedRHSA-2026:3618707.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2481773perl-HTTP-Daemon: HTTP::Daemon: Arbitrary code execution via OS command injection in send_file()

EPSS

Процентиль: 70%
0.01398
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.

CVSS3: 9.1
nvd
2 месяца назад

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.

CVSS3: 9.1
msrc
4 дня назад

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()

CVSS3: 9.1
debian
2 месяца назад

HTTP::Daemon versions before 6.17 for Perl allow OS command injection ...

suse-cvrf
около 1 месяца назад

Security update for perl-HTTP-Daemon

EPSS

Процентиль: 70%
0.01398
Низкий

8.1 High

CVSS3