GHSA-37jv-v9vv-wxwvunknown
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing...
🔗 CVE IDs covered (1)
📋 Description
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks.
These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-5091
- https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b0515f492257438cf07082acf1e10d06e8088a5e.patch
- https://metacpan.org/release/ETHER/Catalyst-Plugin-Authentication-0.10_025/changes
- http://www.openwall.com/lists/oss-security/2026/05/21/19
- https://github.com/advisories/GHSA-37jv-v9vv-wxwv