Critical severity9.8NVD Advisory· Published Mar 26, 2026· Updated May 6, 2026
CVE-2014-125112
CVE-2014-125112
Description
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution.
Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.
Affected products
2- MIYAGAWA/Plack::Middleware::Session::Cookiev5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.openwall.com/lists/oss-security/2026/03/26/2nvdMailing ListThird Party Advisory
- gist.github.com/miyagawa/2b8764af908a0dacd43dnvdThird Party Advisory
- metacpan.org/release/MIYAGAWA/Plack-Middleware-Session-0.23-TRIAL/changesnvdRelease Notes
News mentions
0No linked articles in our index yet.