目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-93710— Perl Dancer2 2.2.0 前路由分发逻辑漏洞

一分钟漏洞结论

影响对象
CVE-2026-93710
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在使用 Perl 的 Dancer2 框架版本中,从 2.0.0 到低于 2.2.0 的版本存在一个漏洞:当某个钩子(hook)因异常(dying hook)拒绝处理某个路由,而异常处理器在 阶段中止(halt)响应时,该被拒绝的路由仍会被分派执行。 具体机制如下: 1. 当一个钩子抛出异常时,会触发 钩子,随后调用清理(cleanup)逻辑,除非失败的那个钩子本身就是异常处理器。 2. 如果异常处理器通过调用响应对象的 方法或设置 属性来中止响应,这种中止操作并不会阻止上述清理过程。清理过程会丢弃调度器(disp

AI 预测 7.5 利用难度: 困难 EPSS 0.63% · P48

影响版本矩阵 1

厂商产品 版本范围状态
None None 2.0.0< 2.2.0 affected

一、 漏洞 CVE-2026-93710 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks
来源: CVE Program / CVE List V5
Vulnerability Description
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup unless the failing hook is the exception handler. A handler that halts does not stop that cleanup, which discards the request, response and session the dispatcher has yet to read, so the refused route runs. The handler has to halt the response object by calling its halt method or setting is_halted: the halt keyword unwinds through with_return before cleanup runs. A check in a before hook is not enforced: the caller gets the refusal, while the route body runs and its writes land.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
抛出异常的清理不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
- - 2.0.0 ~ 2.2.0 -

二、漏洞 CVE-2026-93710 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-93710 的情报信息

请登录查看更多情报信息。

CVE-2026-93710 补丁与修复 (1)

CVE-2026-93710 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93710

暂无评论


发表评论