The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID.
These are predictable or low-entropy sources that are unsuitable for security purposes.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Apply the patch, which requires an upgrade to Mojolicious 9.46 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hayajo
Hayajo mojolicious::sessions::storable |
|
| Vendors & Products |
Hayajo
Hayajo mojolicious::sessions::storable |
Thu, 18 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 18 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sources that are unsuitable for security purposes. | |
| Title | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely | |
| Weaknesses | CWE-338 CWE-340 |
|
| References |
|
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-18T18:47:32.577Z
Reserved: 2026-05-27T10:52:01.931Z
Link: CVE-2026-9692
Updated: 2026-06-18T18:47:18.296Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:55:51Z