PT-2026-98309 · Cpan · Catalyst::Seal
CVE-2026-85491
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Catalyst::Seal versions prior to 0.03
Description
An issue exists where the software memoises how a path is resolved using only the request path as the key. Because action roles may depend on other state such as the HTTP method, content type, scheme, or query, the memoized result may be applied to subsequent requests that do not match the original state. This can lead to two scenarios: a request to a path that resolves to no action (e.g., a GET request to a POST-only path) can disable that path for all subsequent requests, or a request can be routed to a shallower action, bypassing authorization checks like
auto() guarding deeper controllers. The memo persists for the life of the process and has a capacity of 2048 entries.Recommendations
Update Catalyst::Seal to version 0.03 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Catalyst::Seal