{"id":"MGASA-2026-0149","summary":"Updated perl-WWW-Mechanize-Cached, perl-File-XDG & perl-Path-Tiny packages fix security vulnerabilities","details":"WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached\nHTTP responses from a world-writable on-disk cache, enabling local\nresponse forgery and code execution.\n","modified":"2026-05-18T19:15:07.134542Z","published":"2026-05-18T19:12:53Z","upstream":["CVE-2026-8612"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0149.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35533"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/05/15/1"},{"type":"WEB","url":"https://metacpan.org/release/OALDERS/WWW-Mechanize-Cached-2.00/changes"}],"affected":[{"package":{"name":"perl-WWW-Mechanize-Cached","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/perl-WWW-Mechanize-Cached?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0149.json"}},{"package":{"name":"perl-Path-Tiny","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/perl-Path-Tiny?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.150.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0149.json"}},{"package":{"name":"perl-File-XDG","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/perl-File-XDG?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.30.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0149.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}