Skip to content
Fedora 44 perl-Dancer2 Major Deserialization Vulnerability 2026

Fedora 44 perl-Dancer2 Major Deserialization Vulnerability 2026

Linuxsecurity •LinuxSecurity Advisories • September 29, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

Dancer2 is the new generation of Dancer, the lightweight web-framework for

Perl. It is a complete rewrite based on Moo and is meant to be easy and fun.

Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval. deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itself (localised) before loading, rather than relying on YAML.pm's ambient defaults, and the minimum YAML is raised to 1.30.

* Sun Sep 20 2026 Emmanuel Seyman - 2.2.1-1 - Update to 2.2.1 - Downsize version check to make no check the default

* Sun Sep 20 2026 Emmanuel Seyman - 2.2.1-1 - Update to 2.2.1 - Downsize version check to make no check the default

Fedora Update Notification FEDORA-2026-3b893ccf2d 2026-09-29 01:05:47.911295+00:00 Name : perl-Dancer2 Product : Fedora 44 Version : 2.2.1 Release : 1.fc44 URL : Summary : Lightweight yet powerful web application framework Description : Dancer2 is the new generation of Dancer, the lightweight web-framework for Perl. It is a complete rewrite based on Moo and is meant to be easy and fun.

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3b893ccf2d' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Domains (1)

Platforms (1)