Skip to content
Fedora 44 perl-Apache-Session

Fedora 44 perl-Apache-Session

Linuxsecurity LinuxSecurity Advisories May 23, 2026

This update has improvements to generate more secure session IDs (CVE-2026-8503).

* Thu May 14 2026 Paul Howarth - 1.3.19-1 - Update to 1.3.19 (rhbz#2477392) - Apache::Session::Generate::SHA256 used a low-entropy seed (time, PID, rand, stringified hash ref) to derive session identifiers; use Crypt::URandom to generate session ids from a cryptographically secure source, falling back to the hashing method only if Crypt::URandom is unavailable (CVE-2026-8503, similar in scope to CVE-2025-40931 and CVE-2025-40932) - Fix Redis indexes: never cleaned before - Improve resilience and reliability of Patroni driver * Thu Apr 9 2026 Xavier Bachelot - 1.3.18-4 - BR: perl(DBD::Cassandra) to improve test coverage

* Thu May 14 2026 Paul Howarth - 1.3.19-1 - Update to 1.3.19 (rhbz#2477392) - Apache::Session::Generate::SHA256 used a low-entropy seed (time, PID, rand, stringified hash ref) to derive session identifiers; use Crypt::URandom to generate session ids from a cryptographically secure source, falling back to the hashing method only if Crypt::URandom is unavailable (CVE-2026-8503, similar in scope to CVE-2025-40931 and CVE-2025-40932) - Fix Redis indexes: never cleaned before - Improve resilience and reliability of Patroni driver * Thu Apr 9 2026 Xavier Bachelot - 1.3.18-4 - BR: perl(DBD::Cassandra) to improve test coverage

[ 1 ] Bug #2477392 - perl-Apache-Session-Browseable-1.3.19 is available [ 2 ] Bug #2477847 - CVE-2026-8503 perl-Apache-Session-Browseable: perl-Apache-Session-Browseable: Predictable session IDs allow unauthorized system access [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-19d80281b7' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.