Linuxsecurity Critical RCE Vulnerability in Fedora's perl-HTTP-Daemon Affects Multiple Versions
Article Content
- •CVE-2026-8450 allows remote code execution in perl-HTTP-Daemon versions 6.15 and earlier.
- •The vulnerability was fixed in version 6.17, released on May 19, 2026.
- •Users are urged to upgrade to the latest version to prevent exploitation.
A remote code execution vulnerability, CVE-2026-8450, was published on May 27, 2026, affecting perl-HTTP-Daemon versions 6.15 and earlier. The flaw arises from a two-argument open() function in send_file(), which could be exploited through attacker-influenced input, allowing arbitrary file writes and response-body exfiltration. The vulnerability has been patched in version 6.17, released on May 19, 2026, which now utilizes a three-argument open() function to mitigate the risk. Users are advised to upgrade to the latest version to protect against potential exploits. The flaw was reported and patched by Stig Palmquist. Both Fedora 43 and Fedora 44 are affected by this vulnerability, emphasizing the need for immediate action from system administrators.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-8450 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…