Skip to content
Multiple Fedora Perl Modules Vulnerable to Remote Access and Session ID Flaws

Multiple Fedora Perl Modules Vulnerable to Remote Access and Session ID Flaws

First seen 15 Sep 2026, 10:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 11:56 UTC

Recent updates for Fedora's perl-Data-Entropy and perl-Dancer2 modules address critical vulnerabilities. CVE-2026-18536 affects versions before 0.010, allowing attackers to exploit predictable random number generation via unencrypted HTTP sources. This vulnerability can lead to unauthorized admin control. Additionally, CVE-2026-13577 addresses predictable session IDs in perl-Dancer2, which can permit unauthorized system access. Affected versions of perl-Dancer2 generate session IDs from low-entropy sources if certain cryptographic modules are absent. Users are urged to update their systems immediately to mitigate these risks. The updates are available through the 'dnf' package manager.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-20
CVE-2026-13577 published
Vulnerability in perl-Dancer2 allows predictable session IDs, risking unauthorized access.
Linuxsecurity
2026-08-01
CVE-2026-18536 published
Vulnerability in perl-Data-Entropy allows exploitation via unencrypted remote entropy sources.
Linuxsecurity
2026-09-15
Updates released for Fedora modules
Fedora released updates for perl-Data-Entropy and perl-Dancer2 to address critical vulnerabilities.
Linuxsecurity

More articles in this cluster (6)

Following this threat?

Track Fedora and CVE-2026-13577 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed