Header Injection Vulnerability in Plack::Middleware::Security::Common by Perl
CVE-2026-9658

7.3HIGH

Key Information:

Vendor

Rrwo

Vendor
CVE Published:
28 May 2026

What is CVE-2026-9658?

The Plack::Middleware::Security::Common for Perl prior to version 0.13.1 is susceptible to a header injection vulnerability, allowing attackers to manipulate request paths. This vulnerability may enable header injection if the injected data is double-encoded, which the existing security measures fail to block. The implications of such injection could lead to harmful or unauthorized actions within web applications using this middleware. There are uncertainties regarding whether requests with CRLF sequences followed by additional headers can circumvent protections implemented by reverse proxies or how they are managed by Plack-based servers.

Affected Version(s)

Plack::Middleware::Security::Common 0 < 0.13.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.