CVE-2026-13577
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.
Scoring
- CVSS base score
- 0.01
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- EPSS probability
- 0.45%
- CWE
- CWE-340, CWE-338
- Published
- 2026-07-20
- Last modified
- 2026-07-22
Affected products
- CROMEDOME Dancer2
Weakness type
Related vulnerabilities
- CVE-2026-64964 — Generation of Predictable Email Confirmation Token in ATutor
- CVE-2025-14602 — Weak File Name Generation in vsDesk
- CVE-2026-75106 — OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
- CVE-2026-47085 — An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can...
- CVE-2026-56016 — CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
- CVE-2026-9219 — Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
- CVE-2026-11374 — Account Takeover via Predictable SSO Ticket Generation
- CVE-2026-9733 — Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter