๐Ÿ” CVE Alert

CVE-2026-104380

UNKNOWN 0.0

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.

CWE CWE-1385
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new unknown vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/LNATION/Punk-0.55/diff/LNATION/Punk-0.54 metacpan.org: https://metacpan.org/release/LNATION/Punk-0.55/changes