Critical RCE Vulnerability in Fedora's perl-HTTP-Daemon Affects Multiple Versions

Critical RCE Vulnerability in Fedora's perl-HTTP-Daemon Affects Multiple Versions

First seen 19 Jun 2026, 02:54 UTC Linuxsecurity 97% similarity 57.9

Article Content

Browse articles
ThreatCluster

A remote code execution vulnerability, CVE-2026-8450, was published on May 27, 2026, affecting perl-HTTP-Daemon versions 6.15 and earlier. The flaw arises from a two-argument open() function in send_file(), which could be exploited through attacker-influenced input, allowing arbitrary file writes and response-body exfiltration. The vulnerability has been patched in version 6.17, released on May 19, 2026, which now utilizes a three-argument open() function to mitigate the risk. Users are advised to upgrade to the latest version to protect against potential exploits. The flaw was reported and patched by Stig Palmquist. Both Fedora 43 and Fedora 44 are affected by this vulnerability, emphasizing the need for immediate action from system administrators.

Key Points: • CVE-2026-8450 allows remote code execution in perl-HTTP-Daemon versions 6.15 and earlier. • The vulnerability was fixed in version 6.17, released on May 19, 2026. • Users are urged to upgrade to the latest version to prevent exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-05-19
Patch released for perl-HTTP-Daemon
Version 6.17 was released, fixing CVE-2026-8450 by changing the open() function to mitigate risks.
Linuxsecurity
2026-05-27
CVE-2026-8450 published
A remote code execution vulnerability affecting perl-HTTP-Daemon versions 6.15 and earlier was disclosed.
Linuxsecurity
Recent
Users urged to upgrade
System administrators are advised to upgrade to perl-HTTP-Daemon 6.17 to protect against the vulnerability.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story