CVE-2018-25160Disclosure(tokuhirom / http\)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http\

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-28); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
http\

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-28: 1Mentions · 2026-03-08: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-08: 102-2803-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN HTTP::Session2 CVE-2026-3255: Versions before 1.12 may generate weak session ids using the rand() function https://www.openwall.com/lists/oss-security/2026/02/27/12 CVE-2018-25160: Versions through 1.09 do not validate the format of user provided session ids https://www.openwall.com/lists/oss-security/2026/02/27/13

    Post summary

    OpenWALL has disclosed two vulnerabilities in Perl CPAN HTTP::Session2: CVE-2026-3255 (weak session IDs via rand()) and CVE-2018-25160 (no validation of user‑provided session IDs). No exploits, patches, or PoCs are detailed in the notice.

    01021402
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2018-25160 HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session … https://www.cve.org/CVERecord?id=CVE-2018-25160

    Post summary

    The text describes CVE-2018-25160, noting that HTTP::Session2 fails to validate session IDs, allowing code injection, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000146
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptokuhiromhttp\\--

Explore more