CVE-2026-5085Disclosure(mcrawfor / solstice\)

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to the built-in rand() function and the process id. The same method is used in the _generateID method in Solstice::Subsession, which is part of the same distribution. The epoch time may be guessed, if it is not leaked in the HTTP Date header. Stringified hash refences will contain predictable content. The built-in rand() function is seeded by 16-bits and is unsuitable for security purposes. The process id comes from a small set of numbers. Predictable session ids could allow an attacker to gain access to systems.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338CWE-340

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • solstice\

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
solstice\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-13: 3Technical Details · 2026-04-13: 304-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-5085: Solstice::Session versions through 1440 generates session ids insecurely https://www.openwall.com/lists/oss-security/2026/04/13/2

    Post summary

    The advisory announces CVE-2026‑5085, a flaw where Solstice::Session generates insecure session IDs up to version 1440, with no mention of PoC, exploit, or patch.

    00030339
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5085 Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a rand… https://www.cve.org/CVERecord?id=CVE-2026-5085

    Post summary

    The CVE details an insecure session ID generation in Solstice::Session, with MD5 seeded by epoch time and randomness, but no notes on patches, PoCs, or exploitation.

    00000119
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5085 Insecure Session ID Generation in Solstice::Session Perl Versions Through 1440 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5085

    Post summary

    The post announces CVE‑2026‑5085, highlighting an insecure session ID generation flaw in Solstice::Session Perl versions up to 1440, with a link to detailed vulnerability information.

    0000063
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmcrawforsolstice\\--

Explore more