PT-2026-96324 · Dancer2 · Dancer2

CVE-2026-93710

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dancer2 versions 2.0.0 through 2.1.x
Description An issue exists where a route is dispatched even if a dying hook refused it, occurring when the exception handler halts the response in compile hooks. When a hook dies, it triggers core.app.hook exception and subsequently calls cleanup, unless the failing hook is the exception handler itself. If a handler halts, it fails to stop this cleanup process, which discards the request, response, and session that the dispatcher has not yet read, allowing the refused route to execute. This results in a situation where a check in a before hook is not enforced; the caller receives the refusal, but the route body still executes and its writes are processed.
Recommendations Update Dancer2 to version 2.2.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93710
GHSA-V527-R4PX-7VX7

Affected Products

Dancer2