๐Ÿ” CVE Alert

CVE-2013-10075

CRITICAL 9.1

Apache::Session versions through 1.94 for Perl re-creates deleted sessions

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
1th

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

CWE CWE-672
Vendor chorny
Product apache::session
Published May 8, 2026
Last Updated May 8, 2026
Stay Ahead of the Next One

Get instant alerts for chorny apache::session

Be the first to know when new critical vulnerabilities affecting chorny apache::session are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CHORNY / Apache::Session
0 โ‰ค 1.94

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
rt.cpan.org: https://rt.cpan.org/Public/Bug/Display.html?id=83525 openwall.com: http://www.openwall.com/lists/oss-security/2026/05/08/12

Credits

Thomas Sibley