Skip to content
Exploitation of CVE-2026-15743 in Catalyst Plugin

Exploitation of CVE-2026-15743 in Catalyst Plugin

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •CVE-2026-15743 allows unauthorized access to cached content.
  • •Exploitation confirmed by CISA, affecting Catalyst::Plugin::Static::Simple versions up to 0.38.
  • •Patches released on September 20, 2026, to mitigate the vulnerability.

CISA has confirmed the exploitation of a vulnerability (CVE-2026-15743) in the Catalyst::Plugin::Static::Simple for Perl, affecting versions up to 0.38. The flaw allows sensitive data to be exposed due to the Cache-Control header being set to 'public', enabling unauthorized access to cached content. This vulnerability impacts systems using the plugin, particularly those relying on shared reverse proxies or CDN edge caches. The issue was addressed in updates released on September 20, 2026, which allow for overriding the Cache-Control header and setting the Expires header to 0. Administrators are urged to apply the updates promptly to mitigate risks. The vulnerability was published on August 20, 2026, and is currently being exploited in the wild. Organizations using affected versions should verify their systems and apply the necessary patches immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-20
CVE-2026-15743 published
CVE-2026-15743 was published, detailing a vulnerability in Catalyst::Plugin::Static::Simple.
Linuxsecurity
2026-09-20
Patch released
Updates were released to fix CVE-2026-15743, allowing header overrides to prevent data exposure.
Linuxsecurity
Recent
Active exploitation confirmed
CISA confirmed that the vulnerability is being actively exploited in the wild.
Linuxsecurity

More articles in this cluster (4)

Following this threat?

Track Fedora and CVE-2026-15743 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed