VYPR

Dancer2

by Dancer\

Source repositories

CVEs (5)

  • CVE-2026-13577HigJul 20, 2026
    risk 0.46cvss 8.2epss 0.01

    Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom…

  • CVE-2026-93712HigSep 22, 2026
    risk 0.42cvss 7.5epss 0.01

    Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and checks only that the result is a readable…

  • CVE-2026-93710HigSep 22, 2026
    risk 0.42cvss 7.5epss 0.01

    Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup unless the failing hook is the exception handler. A…

  • CVE-2026-93711MedSep 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the PSGI server intact. A server that does not…

  • CVE-2026-93709MedSep 22, 2026
    risk 0.27cvss 5.3epss 0.00

    Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text, while the lookup that follows canonicalises it. A…