
Perl CPAN HTTP::Session2 CVE-2026-3255: Versions before 1.12 may generate weak session ids using the rand() function https://www.openwall.com/lists/oss-security/2026/02/27/12 CVE-2018-25160: Versions through 1.09 do not validate the format of user provided session ids https://www.openwall.com/lists/oss-security/2026/02/27/13
Post summary
The advisory discloses two CVEs in the Perl CPAN HTTP::Session2 module, detailing weak session‑id generation and missing validation, without providing PoC, exploit, or patch information.

