
Perl CPAN CVE-2026-5081: Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 session ids are insecure https://www.openwall.com/lists/oss-security/2026/05/06/6 CVE-2026-40562: Gazelle versions through 0.49 allows HTTP Request Smuggling via Improper Header Precedence https://www.openwall.com/lists/oss-security/2026/05/06/7
Post summary
This brief post announces two new CVEs, outlining their vulnerability types but providing no PoC, tool, exploitation, or patch information.


