CVE-2013-10075General(chorny / apache\)

LOWCVSS 9.1 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-672

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache\

Threat summary

  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-10)
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
apache\

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-05-09: 2Mentions · 2026-05-10: 5Technical Details · 2026-05-09: 2Technical Details · 2026-05-10: 305-0905-10
Signal classification2 categories
General
457.1%
Disclosure
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure2
2026-05-105
Disclosure1General4
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2013-10075: Apache::Session versions through 1.94 re-creates deleted sessions https://www.openwall.com/lists/oss-security/2026/05/08/12 CVE-2026-6659: Crypt::PasswdMD5 versions through 1.42 generates insecure random values for salts https://www.openwall.com/lists/oss-security/2026/05/08/17

    Post summary

    The text announces two CVEs affecting Perl CPAN modules, providing technical details of the vulnerabilities and linking to mailing list discussions, but does not mention PoC, exploit code, active exploitation, patches, or false positives.

    00040582
    4.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-23918 3 - CVE-2026-26980 4 - CVE-2026-41940 5 - CVE-2013-10075 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates five CVE identifiers as trending, without providing additional details or context.

    00020228
    1.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2013-10075-chorny-apache #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only references a URL about CVE-2013-10075, offering no explicit information about the vulnerability, PoC, patch, or exploitation status.

    0000020
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2013-10075 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory Apache::Session versions through 1.94 for Perl re-creates deleted sessions.

    Post summary

    Apache::Session versions up to 1.94 contain a critical flaw that recreates deleted sessions, potentially enabling session hijacking. The advisory provides severity information but no PoC, exploit, or patch details.

    0000021
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Summary Apache::Session versions through 1.94 for Perl re-creates deleted sessions. CVE: CVE-2013-10075 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text gives a brief technical overview of CVE‑2013‑10075, noting it critically impacts session handling, but provides no PoC, exploitation details, or patch information.

    0000020
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2013-10075 · 9.1 → 1.94 CVE: CVE-2013-10075 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The post only lists the CVSS score and vector for CVE‑2013‑10075, providing no additional exploitation or mitigation context.

    0000032
    197 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2013-10075 Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will … https://www.cve.org/CVERecord?id=CVE-2013-10075

    Post summary

    CVE-2013-10075 allows recreation of deleted sessions in Apache::Session up to version 1.94 for Perl.

    00000156
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchornyapache\\--

Explore more