Predictable Session Authentication Vulnerability in Apache AppSamurai for Perl
CVE-2026-19565

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
23 August 2026

What is CVE-2026-19565?

The vulnerable versions of Apache AppSamurai generate session authentication keys based on the clock and process ID, leading to predictable outcomes. The CreateSessionAuthKey function employs a process that can be exploited by attackers aware of the timing of session creation. By enumerating through possible keys, an attacker can potentially recover session cookies, thereby bypassing authentication for secured resources. With a limited space for process IDs and the way time readings are formatted, the vulnerability allows for brute-force attempts against session validation, posing significant risks to the confidentiality and integrity of user sessions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.