PT-2026-98309 · Cpan · Catalyst::Seal

CVE-2026-85491

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Catalyst::Seal versions prior to 0.03
Description An issue exists where the software memoises how a path is resolved using only the request path as the key. Because action roles may depend on other state such as the HTTP method, content type, scheme, or query, the memoized result may be applied to subsequent requests that do not match the original state. This can lead to two scenarios: a request to a path that resolves to no action (e.g., a GET request to a POST-only path) can disable that path for all subsequent requests, or a request can be routed to a shallower action, bypassing authorization checks like auto() guarding deeper controllers. The memo persists for the life of the process and has a capacity of 2048 entries.
Recommendations Update Catalyst::Seal to version 0.03 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85491

Affected Products

Catalyst::Seal