THREAT OPS › Threat News › CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
<p>Posted by Timothy Legge on Aug 25</p>========================================================================<br /> CVE-2026-78655 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-78655<br /> Distribution: Punk-TOTP<br /> Versions: before 0.05<br /> <br />
Indicators of compromise
- CVE-2026-78655cve
- https://metacpan.org/dist/Punk-TOTPurl
Original source: https://seclists.org/oss-sec/2026/q3/575