
CVE-2024-14030: Sereal::Decoder versions from 4.000 through 4.009_002 buffer overwrite in the Zstandard library https://www.openwall.com/lists/oss-security/2026/03/31/9 CVE-2026-5087: PAGI::Middleware::Session::Store::Cookie versions through 0.001003 generates random bytes insecurely https://www.openwall.com/lists/oss-security/2026/03/31/10
Post summary
Two newly disclosed CVEs are highlighted: CVE‑2024‑14030, a buffer overflow in the Zstandard library used by Sereal::Decoder, and CVE‑2026‑5087, insecure random byte generation in PAGI::Middleware::Session::Store::Cookie.
