THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75870 — Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is ab

[NVD] CVE-2026-75870 — Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is ab

mednvdPublished 2026-08-22

CVE-2026-75870 CVSS: None Published: 2026-08-22T14:16:33.813

Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret.

The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is absent. The cookie read and the write-back both default tha

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75870

Same event, other sources