
Perl CPAN CVE-2025-40931: Apache::Session::Generate::MD5 through 1.94 create insecure session id CVE-2026-3257: UnQLite through 0.06 uses potentially insecure version of the UnQLite library CVE-2026-3381: Compress::Raw::Zlib through 2.219 use potentially insecure versions of zlib
Post summary
Three Perl CPAN modules are announced as vulnerable: Apache::Session::Generate::MD5 (insecure session IDs), UnQLite (insecure library version), and Compress::Raw::Zlib (insecure zlib version), with affected versions specified.


