THREAT OPS › Threat News › [NVD] CVE-2026-75870 — Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret.
The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is ab
[NVD] CVE-2026-75870 — Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is ab
CVE-2026-75870 CVSS: None Published: 2026-08-22T14:16:33.813
Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret.
The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is absent. The cookie read and the write-back both default tha
Indicators of compromise
- CVE-2026-75870cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75870