PT-2026-96324 · Dancer2 · Dancer2
CVE-2026-93710
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Dancer2 versions 2.0.0 through 2.1.x
Description
An issue exists where a route is dispatched even if a dying hook refused it, occurring when the exception handler halts the response in
compile hooks. When a hook dies, it triggers core.app.hook exception and subsequently calls cleanup, unless the failing hook is the exception handler itself. If a handler halts, it fails to stop this cleanup process, which discards the request, response, and session that the dispatcher has not yet read, allowing the refused route to execute. This results in a situation where a check in a before hook is not enforced; the caller receives the refusal, but the route body still executes and its writes are processed.Recommendations
Update Dancer2 to version 2.2.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dancer2