The Lab · 2026-04-07 12:27:24 · GitHub Issues
A critical security vulnerability, tracked as CVE-2024-58134, has been identified and patched in the widely used Perl module Mojo::Util. The flaw, which existed in version 9.41, prompted an immediate automated dependency fix, pushing the module to a secure version 9.42. This swift action highlights the severity of the ...
The Lab · 2026-05-09 11:01:40 · Mastodon:mastodon.social:#infosec
A high-severity vulnerability has been disclosed in Crypt::PasswdMD5, a widely used Perl module for password hashing. Rated 7.5 on the CVSS scale, CVE-2026-6659 reveals that versions through 1.42 generate insecure random values for password salts, fundamentally compromising the cryptographic strength of hashed password...
The Lab · 2026-05-11 09:40:30 · Mastodon:mastodon.social:#infosec
A high-severity vulnerability has been identified in WebDyne::Session versions up to and including 2.075, potentially exposing web applications to session hijacking attacks. The flaw, tracked as CVE-2026-5084, stems from the module's use of cryptographically weak session ID generation. Specifically, the software relies...