{"id":"CVE-2026-3256","summary":"HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids","details":"HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids.\n\nHTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the high resolution epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.\n\nThe distribution includes HTTP::session::ID::MD5 which contains a similar flaw, but uses the MD5 hash instead.","modified":"2026-08-12T03:51:38.011093309Z","published":"2026-03-28T18:52:39.917Z","database_specific":{"cwe_ids":["CWE-338","CWE-340"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3256.json","cna_assigner":"CPANSec"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/28/5"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"WEB","url":"https://metacpan.org/release/KTAT/http-session-0.53/source/lib/HTTP/Session/ID/MD5.pm"},{"type":"WEB","url":"https://metacpan.org/release/KTAT/http-session-0.53/source/lib/HTTP/Session/ID/SHA1.pm"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3256.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/TOKUHIROM/http-session-0.54/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3256"},{"type":"PACKAGE","url":"https://github.com/tokuhirom/http-session"},{"type":"ARTICLE","url":"https://security.metacpan.org/docs/guides/random-data-for-security.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tokuhirom/http-session","events":[{"introduced":"0"},{"fixed":"20948a2499bc1b06617a7669a9d155f8e9bfbcd7"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"0.54"}]}}],"versions":["0.53","0.52","0.51","0.50","0.49","0.48","0.46","0.45","0.44","0.43","0.42","0.41","0.40","0.39","0.38","0.37","0.36","0.35","0.34","0.33","0.32","0.31"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3256.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}