Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-8450

38
FAUCET Score

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.

First published: May 27, 2026Last modified: May 27, 2026

Impacted Technologies

VendorProductVersion(s)CPE
OALDERSHTTP::Daemon
>= 0, < 6.17CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.40%
Probability of exploitation in next 30 days
EPSS Percentile
69.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0140 is in the 56th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: azl3 perl-HTTP-Daemon 6.16-1 on Azure Linux 3.0Fixed in: 6.16-2
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (focal)Fixed in: 6.06-1ubuntu0.1+esm1
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (jammy)Fixed in: 6.13-1ubuntu0.2
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (noble)Fixed in: 6.16-1ubuntu0.24.04.1
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (bionic)Fixed in: 6.01-1ubuntu0.1+esm1
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (resolute)Fixed in: 6.16-1ubuntu0.26.04.1
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (trusty)Fixed in: 6.01-1ubuntu0.14.04~esm2
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (xenial)Fixed in: 6.01-1ubuntu0.16.04~esm2
ubuntupatch availablevia ubuntu_usn
Product: libhttp-daemon-perl (questing)Fixed in: 6.16-1ubuntu0.25.10.1

Vendor Advisories (2)

ubuntuUSN-8419-1

HTTP-Daemon vulnerability

Jun 10, 2026
microsoft2026-May/CVE-2026-8450Critical

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()

May 12, 2026

References

access.redhat.com / errata/RHSA-2026:36187
access.redhat.com / errata/RHSA-2026:36188
access.redhat.com / errata/RHSA-2026:36189
access.redhat.com / security/cve/CVE-2026-8450
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-8450.json
github.com / libwww-perl/HTTP-Daemon/commit/945d35141d94490f749640bd4390acd6a2193995.patch
github.com / libwww-perl/HTTP-Daemon/pull/89
metacpan.org / release/OALDERS/HTTP-Daemon-6.17/changes
lists.debian.org / debian-lts-announce/2026/06/msg00028.html
openwall.com / lists/oss-security/2026/05/27/5