{"id":"UBUNTU-CVE-2026-8503","details":"Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of the built-in rand() function, the epoch time, and the PID, that is hashed again. These are predictable, low-entropy sources. Predicable session ids could allow an attacker to gain access to systems. Note that version 1.3.19 has a fallback without warning to use insecure session generation method if the call to Crypt::URandom::urandom fails. However, this is unlikely as Crypt::URandom is a hardcoded requirement of the module. This issue is similar to CVE-2025-40931 for Apache::Session::Generate::MD5.","modified":"2026-05-20T22:03:10.033049780Z","published":"2026-05-15T12:17:00Z","upstream":["CVE-2026-8503"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-8503"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-8503"},{"type":"REPORT","url":"https://lists.security.metacpan.org/cve-announce/msg/40079348/"},{"type":"REPORT","url":"https://github.com/LemonLDAPNG/Apache-Session-Browseable/commit/cc915cbbd266776eec3dd8bf4748b15fa827dbd0"},{"type":"REPORT","url":"https://github.com/LemonLDAPNG/Apache-Session-Browseable/commit/cc915cbbd266776eec3dd8bf4748b15fa827dbd0.patch"},{"type":"REPORT","url":"https://metacpan.org/release/GUIMARD/Apache-Session-Browseable-1.3.19/changes"},{"type":"REPORT","url":"https://metacpan.org/release/GUIMARD/Apache-Session-Browseable-1.3.19/diff/GUIMARD/Apache-Session-Browseable-1.3.18#lib/Apache/Session/Generate/SHA256.pm"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-40931"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-40932"}],"affected":[{"package":{"name":"libapache-session-browseable-perl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libapache-session-browseable-perl?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.2-2","1.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libapache-session-browseable-perl","binary_version":"1.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8503.json"}},{"package":{"name":"libapache-session-browseable-perl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libapache-session-browseable-perl?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.2-1","1.2.8-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libapache-session-browseable-perl","binary_version":"1.2.8-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8503.json"}},{"package":{"name":"libapache-session-browseable-perl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libapache-session-browseable-perl?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.2-1","1.3.3-1","1.3.4-1","1.3.5-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libapache-session-browseable-perl","binary_version":"1.3.5-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8503.json"}},{"package":{"name":"libapache-session-browseable-perl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libapache-session-browseable-perl?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.9-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libapache-session-browseable-perl","binary_version":"1.3.9-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8503.json"}},{"package":{"name":"libapache-session-browseable-perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libapache-session-browseable-perl?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.11-3","1.3.13-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.13-1","binary_name":"libapache-session-browseable-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8503.json"}},{"package":{"name":"libapache-session-browseable-perl","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libapache-session-browseable-perl?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.14-1","1.3.16-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.16-1","binary_name":"libapache-session-browseable-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8503.json"}},{"package":{"name":"libapache-session-browseable-perl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libapache-session-browseable-perl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.16-1","1.3.18-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.18-1","binary_name":"libapache-session-browseable-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8503.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}