Back Linuxsecurity Fedora 44 perl-Catalyst-Plugin-Static-Simple Security Alert 2026
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
The Static::Simple plugin is designed to make serving static content in
your application during development quick and easy, without requiring a
single line of code from you.
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared reverse proxies or CDN edge caches may store and later serve content that was intended to be private, thereby exposing sensitive data to unintended recipients. In this package, the plugin's code is changed to allow the Cache-Control header to be overridden and the Expires header to be set to 0.
* Sun Sep 20 2026 Emmanuel Seyman - 0.38-2 - Apply fix for CVE-2026-15743 * Sun Jul 19 2026 Emmanuel Seyman - 0.38-1 - Update to 0.38
* Sun Sep 20 2026 Emmanuel Seyman - 0.38-2 - Apply fix for CVE-2026-15743 * Sun Jul 19 2026 Emmanuel Seyman - 0.38-1 - Update to 0.38
[ 1 ] Bug #2536982 - CVE-2026-15743 perl-Catalyst-Plugin-Static-Simple: Catalyst::Plugin::Static::Simple: Information disclosure via public caching of authenticated responses [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2d96cf2594' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
