CVE-2018-25160

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tokuhirom:http\:\:session2:*:*:*:*:*:perl:*:*

History

18 Mar 2026, 19:25

Type Values Removed Values Added
References () https://github.com/tokuhirom/HTTP-Session2/commit/813838f6d08034b6a265a70e53b59b941b5d3e6d.patch - () https://github.com/tokuhirom/HTTP-Session2/commit/813838f6d08034b6a265a70e53b59b941b5d3e6d.patch - Patch
References () https://metacpan.org/pod/Cache::Memcached::Fast::Safe - () https://metacpan.org/pod/Cache::Memcached::Fast::Safe - Third Party Advisory
References () https://metacpan.org/release/TOKUHIROM/HTTP-Session2-1.10/source/Changes - () https://metacpan.org/release/TOKUHIROM/HTTP-Session2-1.10/source/Changes - Product, Release Notes
References () http://www.openwall.com/lists/oss-security/2026/02/27/13 - () http://www.openwall.com/lists/oss-security/2026/02/27/13 - Mailing List, Third Party Advisory
Summary
  • (es) Las versiones de HTTP::Session2 hasta la 1.09 para Perl no validan el formato de los ID de sesión proporcionados por el usuario, lo que permite la inyección de código u otro impacto dependiendo del backend de la sesión. Por ejemplo, si una aplicación utiliza memcached para el almacenamiento de sesiones, entonces puede ser posible para un atacante remoto inyectar comandos de memcached en el valor del ID de sesión.
CWE NVD-CWE-noinfo
First Time Tokuhirom
Tokuhirom http\
CPE cpe:2.3:a:tokuhirom:http\:\:session2:*:*:*:*:*:perl:*:*

03 Mar 2026, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

28 Feb 2026, 01:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/02/27/13 -

27 Feb 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 21:16

Updated : 2026-03-18 19:25


NVD link : CVE-2018-25160

Mitre link : CVE-2018-25160

CVE.ORG link : CVE-2018-25160


JSON object : View

Products Affected

tokuhirom

  • http\
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo