
Perl CPAN July 2026 disclosures CVE-2026-56016: CGI::Session::ID::md5 before 4.49 generate predictable session ids from low-entropy sources https://www.openwall.com/lists/oss-security/2026/07/01/6 CVE-2025-15646: HTML::Gumbo before 0.19 disclose heap memory via type confusion https://www.openwall.com/lists/oss-security/2026/07/01/7
Post summary
The message announces two new Perl module CVE disclosures, giving technical details but no exploits, patches, or reported abuse.

