CVE-2026-5082Disclosure(tokuhirom / amon2\)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes using SHA-1 hash seeded with the built-in rand() function, the PID, and the high resolution epoch time. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Amon2::Plugin::Web::CSRFDefender versions before 7.00 were part of Amon2, which was vulnerable to insecure session ids due to CVE-2025-15604. Note that the author has deprecated this module.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338CWE-340

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • amon2\

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
amon2\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Mentions · 2026-04-13: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-13: 104-0804-0904-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-081
General1
2026-04-091
Disclosure1
2026-04-131
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-5082: Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 generate an insecure session id https://www.openwall.com/lists/oss-security/2026/04/08/6 CVE-2026-5083: Ado::Sessions versions through 0.935 generates insecure session ids https://www.openwall.com/lists/oss-security/2026/04/08/7

    Post summary

    The message announces two new CVEs in Perl modules that produce insecure session IDs, detailing the affected version ranges and linking to a mailing list discussion.

    00051511
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5082 Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes … https://www.cve.org/CVERecord?id=CVE-2026-5082

    Post summary

    The text discloses that CVE‑2026‑5082 causes insecure session ID generation in specific Amon2 plugin versions, providing technical details but no PoC, exploit, or remediation information.

    00000161
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5082 Insecure Session ID Generation in Amon2::Plugin::Web::CSRFDefender 7.00-7.03 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5082

    Post summary

    The post announces CVE-2026-5082 and links to a vulnerability detail page, offering no technical or exploitation information.

    0000069
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptokuhiromamon2\\csrfdefender-

Explore more