Perlbal is a lightweight load-balancing and web-proxying application written in Perl that serves as a request router in web infrastructure, with its vulnerability exposure centered on a single product line. The durable signal reflects its role handling untrusted network input, with recurring weaknesses in improper input validation and path-traversal conditions that are characteristic of web-facing proxy and routing components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Perlbal over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1652MEDIUM Directory traversal vulnerability in the _serve_request_multiple function in lib/Perlbal/ClientHTTPBase.pm in Perlbal before 1.70, when concat get is enabled, allows remote attacke | Apr 2, 2008 | 5.0 | 16 | NO | NO |
CVE-2008-1532MEDIUM Perlbal before 1.70, when buffered upload is enabled, allows remote attackers to cause a denial of service (crash) via a zero-byte chunked upload. | Mar 28, 2008 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Perlbal.
Media articles that mention a CVE ID that affects a product developed by Perlbal — matched by CVE ID, not by vendor name.