CVE-2026-19565Disclosure

LOWCVSS 3.7 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds of SHA-256, each over a fresh Time::HiRes reading formatted to six decimal places, the running digest, and the process id. CreateSession calls it with an empty key source on every login, and the optional Keysource directive is the only route to the other branch. The result is 64 hex characters. The microsecond field of the first reading takes one of a million values, the later readings follow it within microseconds, and the process id is drawn from a small range. The key is returned to the browser as the session cookie, and is combined with the configured server key to compute the session id and to encrypt the stored session data. An attacker who knows the second in which a session was created and the process id of the worker that created it can enumerate candidate keys and recover the victim's cookie, bypassing authentication for the protected resources. Each candidate has to be tried against the server, which validates the cookie with a key the attacker does not hold.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-341

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-23: 2Technical Details · 2026-08-23: 208-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19565 Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. Creat… https://www.cve.org/CVERecord?id=CVE-2026-19565 ----- Traducción: CVE-2026-19565 Apa… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-19565, describing a predictable session authentication key issue in Apache::AppSamurai::Util. No proof of concept, exploit, or mitigation information is provided.

    0000052
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19565 Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. Creat… https://www.cve.org/CVERecord?id=CVE-2026-19565

    Post summary

    A new vulnerability (CVE-2026-19565) is disclosed: Apache::AppSamurai::Util generates predictable session keys based on the clock and PID.

    00000911
    58.0K followersView on X

Explore more