Chorny's vulnerability footprint centers on a single Apache-related product and is characterized by cryptographic and randomness-handling weaknesses, including predictable number generation, weak pseudo-random number generators, and resource lifecycle issues. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chorny over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5081CRITICAL Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure.
Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the v | May 6, 2026 | 9.1 | 39 | NO | NO |
CVE-2013-10075CRITICAL Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a sessi | May 8, 2026 | 9.1 | 35 | NO | NO |
CVE-2025-40931CRITICAL Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id.
Apache::Session::Generate::MD5 generates session ids insecurely. The default session id g | Mar 5, 2026 | 9.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chorny.
Media articles that mention a CVE ID that affects a product developed by Chorny — matched by CVE ID, not by vendor name.