Fedora 43 and 44 perl-Catalyst-Plugin Vulnerable to Timing Attacks

Fedora 43 and 44 perl-Catalyst-Plugin Vulnerable to Timing Attacks

First seen 2 Jun 2026, 06:22 UTC Linuxsecuritymetacpan.org 97% similarity 57.9

Article Content

Browse articles
ThreatCluster

Versions of Catalyst::Plugin::Authentication for Perl up to 0.10024 are vulnerable to timing attacks, which could allow attackers to guess passwords or hashes. This vulnerability is documented as CVE-2026-5091, published on May 21, 2026. The issue arises from the use of Perl's built-in eq comparison, leading to discrepancies in timing. Version 0.10026 addresses this vulnerability and was released on May 24, 2026. Users of Fedora 43 and 44 are advised to upgrade to this version to mitigate the risk. The vulnerability affects all systems using the affected versions of the plugin. The update can be installed via the dnf update program. Security professionals should prioritize this update to protect against potential exploitation.

Key Points: • Catalyst::Plugin::Authentication versions up to 0.10024 are vulnerable to timing attacks. • CVE-2026-5091 was published on May 21, 2026, detailing the vulnerability. • Version 0.10026 released on May 24, 2026, fixes the timing attack issue.

ThreatCluster AI

Timeline

2026-05-21
CVE-2026-5091 published
CVE-2026-5091 details a timing attack vulnerability in Catalyst::Plugin::Authentication versions up to 0.10024.
Linuxsecurity
2026-05-24
Version 0.10026 released
Version 0.10026 of Catalyst::Plugin::Authentication was released to fix CVE-2026-5091.
Linuxsecurity
2026-06-02
Vulnerability reported in Fedora 44
Similar vulnerabilities were reported for Fedora 44, reiterating the need for updates to version 0.10026.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story