CVE-2014-125112Disclosure(miyagawa / plack\)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-565

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • plack\

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-10)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
plack\

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-26: 2Mentions · 2026-03-28: 1Mentions · 2026-05-10: 4Technical Details · 2026-03-26: 2Technical Details · 2026-03-28: 1Technical Details · 2026-05-10: 303-2603-2805-10
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-03-281
Disclosure1
2026-05-104
Disclosure3General1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2014-125112: Plack::Middleware::Session::Cookie versions through 0.21 allows remote code execution https://www.openwall.com/lists/oss-security/2026/03/26/2 CVE-2026-4851: GRID::Machine remote-to-local code execution https://www.openwall.com/lists/oss-security/2026/03/26/6

    Post summary

    The text announces two CVEs—CVE-2014-125112, a remote code execution flaw in Plack::Middleware::Session::Cookie, and CVE-2026-4851, a remote‑to‑local code execution issue in GRID::Machine—providing links to mailing list discussions for further details.

    00060297
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2014-125112 Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a secu… https://www.cve.org/CVERecord?id=CVE-2014-125112

    Post summary

    The text announces a remote code execution vulnerability in Plack::Middleware::Session::Cookie versions through 0.21 for Perl.

    00010116
    56.8K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2014-125112-miyagawa-plack #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text merely points to a CVE link with hashtags, providing no actionable information or detailed context about the vulnerability.

    0000015
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2014-125112 (CVSS 9.8) — miyagawa plack\. CVE: CVE-2014-125112 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text is a brief disclosure of CVE‑2014‑125112, noting its critical severity and CVSS score, but it offers no information on exploitation, mitigation, or patches.

    0000014
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Summary Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. CVE: CVE-2014-125112 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A critical CVE-2014-125112 vulnerability in Plack::Middleware::Session::Cookie allows remote code execution; no PoC, exploit, or patch details are provided, nor is there evidence of active exploitation.

    0000017
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2014-125112 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution.

    Post summary

    The text announces a critical advisory for CVE-2014-125112, detailing remote code execution in Plack::Middleware::Session::Cookie up to version 0.21, with full CVSS scoring and severity classification.

    0000023
    197 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2014-125112 - Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution Intel Report: https://ift.tt/0D6lyzL

    Post summary

    CVE-2014-125112 enables remote code execution in Plack::Middleware::Session::Cookie up to version 0.21 for Perl, as reported in an Intel report; no PoC, exploit tool, active exploitation, patch, or debunking claim is mentioned.

    0000023
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmiyagawaplack\\cookie-

Explore more