Back Linuxsecurity Fedora 43 perl-HTTP-Daemon Moderate RCE Risk CVE-2026
Changes: 6.17 2026-05-19 23:11:06Z Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker- influenced input. send_file() now uses 3-arg open() with an explicit ' path', etc.) are no longer interpreted. send_file() now also returns '0E0' (true zero) on a successful zero-byte transfer so callers can distinguish empty file from open failure (undef). See for the advisory. Reported and patched by Stig Palmquist (stigtsp). (Stig Palmquist, Olaf Alders)
* Wed May 20 2026 Michal Josef Špaček - 6.17-1 - 6.17 bump
* Wed May 20 2026 Michal Josef Špaček - 6.17-1 - 6.17 bump
[ 1 ] Bug #2480076 - perl-HTTP-Daemon-6.17 is available
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f276b2154e' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
