CVE-2026-5091 PUBLISHED

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks

Assigner: CPANSec
Reserved: 28.03.2026 Published: 21.05.2026 Updated: 22.05.2026

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks.

These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

Product Status

Vendor JJNAPIORK
Product Catalyst::Plugin::Authentication
Versions Default: unaffected
  • affected from 0 to 0.10024 (incl.)

Solutions

Upgrade to version 0.10026 or later.

References

Problem Types

  • CWE-208 Observable Timing Discrepancy CWE