Back Linuxsecurity Fedora 44 perl-Apache-Session
This update has improvements to generate more secure session IDs (CVE-2026-8503).
* Thu May 14 2026 Paul Howarth - 1.3.19-1 - Update to 1.3.19 (rhbz#2477392) - Apache::Session::Generate::SHA256 used a low-entropy seed (time, PID, rand, stringified hash ref) to derive session identifiers; use Crypt::URandom to generate session ids from a cryptographically secure source, falling back to the hashing method only if Crypt::URandom is unavailable (CVE-2026-8503, similar in scope to CVE-2025-40931 and CVE-2025-40932) - Fix Redis indexes: never cleaned before - Improve resilience and reliability of Patroni driver * Thu Apr 9 2026 Xavier Bachelot - 1.3.18-4 - BR: perl(DBD::Cassandra) to improve test coverage
* Thu May 14 2026 Paul Howarth - 1.3.19-1 - Update to 1.3.19 (rhbz#2477392) - Apache::Session::Generate::SHA256 used a low-entropy seed (time, PID, rand, stringified hash ref) to derive session identifiers; use Crypt::URandom to generate session ids from a cryptographically secure source, falling back to the hashing method only if Crypt::URandom is unavailable (CVE-2026-8503, similar in scope to CVE-2025-40931 and CVE-2025-40932) - Fix Redis indexes: never cleaned before - Improve resilience and reliability of Patroni driver * Thu Apr 9 2026 Xavier Bachelot - 1.3.18-4 - BR: perl(DBD::Cassandra) to improve test coverage
[ 1 ] Bug #2477392 - perl-Apache-Session-Browseable-1.3.19 is available [ 2 ] Bug #2477847 - CVE-2026-8503 perl-Apache-Session-Browseable: perl-Apache-Session-Browseable: Predictable session IDs allow unauthorized system access [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-19d80281b7' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
