Skip to content
Critical Deserialization Vulnerability in Fedora 44 and 45 perl-Dancer2

Critical Deserialization Vulnerability in Fedora 44 and 45 perl-Dancer2

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •Critical deserialization vulnerability affects Fedora 44 and 45 perl-Dancer2.
  • •CISA confirms exploitation in the wild, increasing urgency for patching.
  • •Immediate updates are available via the dnf package manager.

A major deserialization vulnerability has been identified in the perl-Dancer2 framework affecting Fedora 44 and 45. CISA has confirmed exploitation of this flaw, which allows arbitrary object instantiation through YAML deserialization. The vulnerability arises from the Dancer2::Serializer::YAML::deserialize method, which improperly handles request bodies. This vulnerability is particularly concerning as it can lead to the execution of arbitrary code. The affected versions are perl-Dancer2 2.2.1 in both Fedora 44 and 45. Users are urged to apply the available patches immediately to mitigate the risk. The updates set $YAML::LoadBlessed and $YAML::LoadCode to 0 before loading, addressing the security issue. The updates can be installed using the dnf package manager. As of today, both updates have been released and are available for installation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
CISA confirms exploitation
CISA has confirmed that the deserialization vulnerability in perl-Dancer2 is being actively exploited.
Linuxsecurity
2026-09-29
Fedora updates released
Updates for perl-Dancer2 2.2.1 have been released for both Fedora 44 and 45 to address the vulnerability.
Linuxsecurity

More articles in this cluster (2)