Proxy Vulnerability in Plack::App::Prerender from Perl
CVE-2026-17552
Currently unrated
What is CVE-2026-17552?
Versions of Plack::App::Prerender prior to 0.3.0 are susceptible to a proxy vulnerability due to unvalidated concatenation of REQUEST_URI. Specifically, when the rewrite base is a plain string, any submitted path is appended without checks, allowing attackers to manipulate the host by crafting requests containing an @-sign. This could enable unauthorized access to internal or restricted systems, as the system may inadvertently handle requests to unintended destinations. Administrators should upgrade to the latest version to mitigate this risk.
Affected Version(s)
Plack::App::Prerender 0 < 0.3.0
