๐Ÿ” CVE Alert

CVE-2026-75870

CRITICAL 9.1

Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret

CVSS Score
9.1
EPSS Score
0.2%
EPSS Percentile
12th

Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is absent. The cookie read and the write-back both default that key to the empty string, so a declaration with no secret option, or with an undefined or empty one, signs and verifies with a zero-length HMAC-SHA256 key. An attacker who knows the cookie format can then mint one offline carrying any contents the session holds, such as a user identifier or a role. Nothing marks the misconfiguration at runtime: cookies are well formed and sessions round-trip as expected.

CWE CWE-1394
Published Aug 22, 2026
Last Updated Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new critical vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/LNATION/Punk-0.17/source/include/punk/punk_session.h metacpan.org: https://metacpan.org/release/LNATION/Punk-0.17/view/lib/Punk.pm metacpan.org: https://metacpan.org/release/LNATION/Punk-0.18/source/Changes openwall.com: http://www.openwall.com/lists/oss-security/2026/08/22/5