CVE-2026-5083
Ado::Sessions versions through 0.935 for Perl generates insecure session ids.
The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.
Predicable session ids could allow an attacker to gain access to systems.
Note that Ado is no longer maintained, and has been removed from the CPAN index. It is still available on BackPAN.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-338, CWE-340
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-5083",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-5083",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-08T16:08:27.234472Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://github.com/kberov/Ado",
"vendor": "BEROV",
"product": "Ado::Sessions",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "0.935"
}
],
"packageName": "Ado",
"programFiles": [
"lib/Ado/Session.pm"
],
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "Ado::Sessions::generate_id"
}
]
}
]
}
],
"published": "2026-04-08T06:16:29.163",
"references": [
{
"url": "https://backpan.perl.org/authors/id/B/BE/BEROV/Ado-0.935.tar.gz",
"tags": [
"Product"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://github.com/kberov/Ado/issues/112",
"tags": [
"Issue Tracking"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://security.metacpan.org/docs/guides/random-data-for-security.html",
"tags": [
"Third Party Advisory"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/04/08/7",
"tags": [
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-338"
},
{
"lang": "en",
"value": "CWE-340"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ado::Sessions versions through 0.935 for Perl generates insecure session ids.\n\nThe session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.\n\nPredicable session ids could allow an attacker to gain access to systems.\n\nNote that Ado is no longer maintained, and has been removed from the CPAN index. It is still available on BackPAN."
},
{
"lang": "es",
"value": "Las versiones de Ado::Sessions hasta la 0.935 para Perl generan identificadores de sesión inseguros.\n\nEl identificador de sesión se genera a partir de un hash SHA-1 sembrado con la función rand incorporada, el tiempo de época y el PID. El PID provendrá de un pequeño conjunto de números, y el tiempo de época puede ser adivinado, si no se filtra del encabezado HTTP Date. La función rand incorporada no es adecuada para uso criptográfico.\n\nIdentificadores de sesión predecibles podrían permitir a un atacante obtener acceso a los sistemas.\n\nTenga en cuenta que Ado ya no recibe mantenimiento y ha sido eliminado del índice CPAN. Todavía está disponible en BackPAN."
}
],
"lastModified": "2026-07-24T20:10:00.147",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:berov:ado\\:\\:sessions:*:*:*:*:*:perl:*:*",
"vulnerable": true,
"matchCriteriaId": "1DF482FB-2415-4BAE-B16A-99EA9F0CD85B",
"versionEndIncluding": "0.935"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}