CVE-2026-56016

NameCVE-2026-56016
DescriptionCGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All three are predictable, low-entropy sources: the PID is drawn from a small range, the epoch time can be guessed or read from the HTTP Date header, and Perl's rand() is unsuitable for security purposes because it is predictable and reversible. An attacker who predicts a session id can impersonate the corresponding session and bypass authentication.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1141197

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libcgi-session-perl (PTS)bullseye4.48-3vulnerable
bookworm, trixie4.48-4vulnerable
forky, sid4.49-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libcgi-session-perlsource(unstable)4.49-11141197

Notes

[trixie] - libcgi-session-perl <no-dsa> (Minor issue)
https://lists.security.metacpan.org/cve-announce/msg/41439279/

Search for package or bug name: Reporting problems