CVE-2026-3256
HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the high resolution epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. The distribution includes HTTP::session::ID::MD5 which contains a similar flaw, but uses the MD5 hash instead.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.53%
- CWE
- CWE-340, CWE-338
- Published
- 2026-03-28
- Last modified
- 2026-09-17
Affected products
- KTAT HTTP::Session
Weakness type
Related vulnerabilities
- CVE-2025-69286 — RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
- CVE-2024-7558 — JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K
- CVE-2025-68701 — Jervis has Deterministic AES IV Derivation from Passphrase
- CVE-2025-62294 — Predictable Generation of Password Recovery Token
- CVE-2025-15604 — Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions
- CVE-2026-2439 — Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids
- CVE-2025-40926 — Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely
- CVE-2026-75106 — OpnForm Editable Submission Secret Derivation via Empty Hashids Salt