Session Cookie Forgery in Punk for Perl by LNATION
CVE-2026-75870

Currently unrated

Key Information:

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-75870?

The vulnerability in Punk for Perl allows attackers to exploit session cookie forgery due to an empty default HMAC key. When a session is declared without a secret, the options are frozen to the application. This misconfiguration leads to the read and write-back processes defaulting to an empty string for the HMAC key. Attackers aware of the cookie format can craft malicious cookies offline containing unauthorized information, such as user identifiers or privileges, without any immediate indication of compromise during runtime. Ensuring proper session management and configuration is essential to safeguard against this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.