CVE-2025-40931 describes a critical vulnerability in Apache::Session::Generate::MD5 versions through 1.94 for Perl, where insecure session IDs are generated. The module uses predictable inputs like the rand() function, epoch time, and PID, making session IDs guessable. This flaw carries a CVSS score of 9.1 (CRITICAL), indicating a high risk of compromise (CWE-338, CWE-340) where an unauthenticated attacker could gain full access to systems. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.94CPE matchmatch criteria | cpe:2.3:a:chorny:apache\:\:session\:\:generate\:\:md5:*:*:*:*:*:perl:*:* | ||
>= 0, <= 1.94CPE match | cpe:2.3:a:chorny:apache\:\:session\:\:generate\:\:md5:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.