Header Injection Vulnerability in Plack::Middleware::Security::Common by Perl
CVE-2026-9658
7.3HIGH
What is CVE-2026-9658?
The Plack::Middleware::Security::Common for Perl prior to version 0.13.1 is susceptible to a header injection vulnerability, allowing attackers to manipulate request paths. This vulnerability may enable header injection if the injected data is double-encoded, which the existing security measures fail to block. The implications of such injection could lead to harmful or unauthorized actions within web applications using this middleware. There are uncertainties regarding whether requests with CRLF sequences followed by additional headers can circumvent protections implemented by reverse proxies or how they are managed by Plack-based servers.
Affected Version(s)
Plack::Middleware::Security::Common 0 < 0.13.1
