CVE-2026-15743

Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to requests from other users. (This includes requests with an Authorization header.) Configuring the expires time to "0" to disable caching, as documented, is ignored.

Scoring

Severity
MEDIUM
CVSS base score
5.7
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS probability
0.32%
CWE
CWE-524
Published
2026-08-20
Last modified
2026-08-28

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs