
Perl CPAN CVE-2026-5082: Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 generate an insecure session id https://www.openwall.com/lists/oss-security/2026/04/08/6 CVE-2026-5083: Ado::Sessions versions through 0.935 generates insecure session ids https://www.openwall.com/lists/oss-security/2026/04/08/7
Post summary
The message announces two new CVEs in Perl modules that produce insecure session IDs, detailing the affected version ranges and linking to a mailing list discussion.


