CVE-2026-3256 identifies a critical vulnerability in HTTP::Session versions through 0.53 for Perl, where session IDs are generated insecurely using predictable seeds like `rand()`, epoch time, and PID, making them easily guessable. This flaw affects applications utilizing the module, such as `ktat http`. Rated with a CVSS score of 9.8 (CRITICAL), the vulnerability can be exploited remotely over the network with low complexity and no user interaction or privileges required. Successful exploitation could lead to high impact on confidentiality, integrity, and availability, potentially allowing session hijacking and unauthorized access. Currently, there is no evidence of active exploitation, no public exploit code available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.53CPE matchmatch criteria | cpe:2.3:a:ktat:http\:\:session:*:*:*:*:*:perl:*:* | ||
>= 0, < 0.54CPE match | cpe:2.3:a:ktat:http\:\:session:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.