{"id":"UBUNTU-CVE-2026-7381","details":"Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to \"X-Accel-Redirect\" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the \"X-Accel-Redirect\" type.","modified":"2026-05-26T19:29:32.050088786Z","published":"2026-04-29T23:16:00Z","upstream":["CVE-2026-7381"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-7381"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-7381"},{"type":"REPORT","url":"https://lists.security.metacpan.org/cve-announce/msg/39467666/"}],"affected":[{"package":{"name":"libplack-perl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libplack-perl?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0037-1","1.0038-1","1.0039-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libplack-perl","binary_version":"1.0039-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7381.json"}},{"package":{"name":"libplack-perl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libplack-perl?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0042-1","1.0044-1","1.0045-1","1.0047-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0047-1","binary_name":"libplack-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7381.json"}},{"package":{"name":"libplack-perl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libplack-perl?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0047-1","1.0047-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libplack-perl","binary_version":"1.0047-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7381.json"}},{"package":{"name":"libplack-perl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libplack-perl?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0048-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libplack-perl","binary_version":"1.0048-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7381.json"}},{"package":{"name":"libplack-perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libplack-perl?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0050-1","1.0051-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0051-1","binary_name":"libplack-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7381.json"}},{"package":{"name":"libplack-perl","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libplack-perl?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0051-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libplack-perl","binary_version":"1.0051-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7381.json"}},{"package":{"name":"libplack-perl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libplack-perl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0051-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libplack-perl","binary_version":"1.0051-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7381.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}