Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104380— Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one

Quick assessment

Affected
CVE-2026-104380
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Perl 版的 Punk 框架在 0.48 至 0.55 版本(不含 0.55)中存在安全漏洞。该漏洞涉及对 Extended CONNECT 请求的路由处理:在 函数中,Extended CONNECT 请求会被错误地路由到任何 GET 路由,且在此过程中未进行 Origin(源站)检查。 在 HTTP/2 和 HTTP/3 协议中,WebSocket 握手请求会以 Extended CONNECT 的形式到达。由于该请求被匹配为 GET 请求,因此它会被转发至所有 GET 路由、API 操作以及挂载点(moun

AI Predicted 7.5 Difficulty: Easy

I. Basic Information for CVE-2026-104380

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one
Source: CVE Program / CVE List V5
Vulnerability Description
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1385
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0.48 ~ 0.55 -

II. Public POCs for CVE-2026-104380

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104380

请登录查看更多情报信息。

Other References for CVE-2026-104380 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104380

No comments yet


Leave a comment