๐Ÿ” CVE Alert

CVE-2026-5091

MEDIUM 5.1

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks

CVSS Score
5.1
EPSS Score
0.0%
EPSS Percentile
2th

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

CWE CWE-208
Vendor jjnapiork
Product catalyst::plugin::authentication
Published May 21, 2026
Last Updated May 22, 2026
Stay Ahead of the Next One

Get instant alerts for jjnapiork catalyst::plugin::authentication

Be the first to know when new medium vulnerabilities affecting jjnapiork catalyst::plugin::authentication are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

JJNAPIORK / Catalyst::Plugin::Authentication
0 โ‰ค 0.10024

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/ETHER/Catalyst-Plugin-Authentication-0.10_025/changes github.com: https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b0515f492257438cf07082acf1e10d06e8088a5e.patch openwall.com: http://www.openwall.com/lists/oss-security/2026/05/21/19