Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-13577— Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable

Quick assessment

Affected
CVE-2026-13577
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PerlDancer Dancer2是PerlDancer组织的一个网络应用开发框架 PerlDancer Dancer2 2.1.0及之前版本存在加密问题漏洞,该漏洞源于CSPRNG modules不可用时Dancer2::Core::Role::SessionFactory::generate_id会退回到使用内置rand函数生成的session id,这些session id使用低熵且易猜测的源(如SHA-1哈希、内部计数器、进程ID等)生成,可预测的session id允许攻击者获得系统访问权限。

AI Predicted 5.3 Difficulty: Hard EPSS 0.57% · P45

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
None None < 2.2.0 affected

I. Basic Information for CVE-2026-13577

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable
Source: CVE Program / CVE List V5
Vulnerability Description
Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
可预测问题
Source: CVE Program / CVE List V5
Vulnerability Title
PerlDancer Dancer2 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PerlDancer Dancer2是PerlDancer组织的一个网络应用开发框架 PerlDancer Dancer2 2.1.0及之前版本存在加密问题漏洞,该漏洞源于CSPRNG modules不可用时Dancer2::Core::Role::SessionFactory::generate_id会退回到使用内置rand函数生成的session id,这些session id使用低熵且易猜测的源(如SHA-1哈希、内部计数器、进程ID等)生成,可预测的session id允许攻击者获得系统访问权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 2.2.0 -

II. Public POCs for CVE-2026-13577

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13577

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-13577 (1)

Vendor Advisories for CVE-2026-13577 (1)

Other References for CVE-2026-13577 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-13577

No comments yet


Leave a comment