Kazeburo maintains Plack, a Perl web application server framework whose vulnerability exposure centers on cryptographic and request-parsing weaknesses including predictable number generation, HTTP request smuggling, and weak pseudo-random number generators. These issues reflect the security challenges inherent to request-handling and session-management logic in application servers. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kazeburo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40926CRITICAL Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely.
The default session id generator returns a SHA-1 hash seeded with the built-in r | Mar 5, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-40562HIGH Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence.
Gazelle incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chun | May 6, 2026 | 7.5 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kazeburo.
Media articles that mention a CVE ID that affects a product developed by Kazeburo — matched by CVE ID, not by vendor name.