« Volver al listado

CVE-2026-13577

Estado: AplazadaAlta (8.2)—

Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable.

Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available.

The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function).

Leer descripción completaMostrar menos

These are all low-entropy and easily guessed sources.

The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications.

Predictable session ids could allow an attacker to gain access to systems.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N, PR:N, UI:N indica explotación remota sin privilegios (T1190). Sesiones predecibles permiten falsificación de identidad (T1078.001) y acceso a datos de sesión (T1552.007 credential access).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-13577",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-13577",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-20T13:05:03.182340Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/PerlDancer/Dancer2",
          "modules": [
            "Dancer2"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.2.0",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:cpan/Dancer2",
          "packageName": "Dancer2",
          "programFiles": [
            "lib/Dancer2/Core/Role/SessionFactory.pm"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Dancer2::Core::Role::SessionFactory::generate_id"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-20T08:16:28.987",
  "references": [
    {
      "url": "https://github.com/PerlDancer/Dancer2/blob/v2.1.0/lib/Dancer2/Core/Role/SessionFactory.pm#L142",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://github.com/PerlDancer/Dancer2/issues/1807",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://github.com/PerlDancer/Dancer2/pull/1804",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/CROMEDOME/Dancer2-2.2.0/changes",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5080",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-338"
        },
        {
          "lang": "en",
          "value": "CWE-340"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable.\n\nDancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available.\n\nThe fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function).\n\nThese are all low-entropy and easily guessed sources.\n\nThe built-in rand() function is seeded with 32-bits and considered unsuitable for security applications.\n\nPredictable session ids could allow an attacker to gain access to systems."
    }
  ],
  "lastModified": "2026-09-20T11:16:56.817",
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}