CVE-2026-7381Disclosure(miyagawa / plack\)

LOWCVSS 9.1 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the "X-Accel-Redirect" type.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-441CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • plack\

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-18)
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
plack\

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-04-29: 2Mentions · 2026-04-30: 2Mentions · 2026-05-18: 4Technical Details · 2026-04-29: 2Technical Details · 2026-04-30: 2Technical Details · 2026-05-18: 304-2904-3005-18
Signal classification2 categories
Disclosure
675.0%
General
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure2
2026-04-302
Disclosure2
2026-05-184
Disclosure2General2
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-7111: Text::CSV_XS: Use-after-free, may enable type confusion or memory corruption https://www.openwall.com/lists/oss-security/2026/04/29/17 CVE-2026-7381: Plack::Middleware::XSendfile: Client-controlled path rewriting https://www.openwall.com/lists/oss-security/2026/04/29/27

    Post summary

    The text discloses two Perl CPAN module vulnerabilities with technical details, but provides no evidence of PoC, exploitation tools, active attacks, patches, or false‑positive claims.

    00051286
    4.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Summary Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. CVE: CVE-2026-7381 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory identifies a critical vulnerability in Plack::Middleware::XSendfile that allows client-controlled path rewriting, providing technical details and CVSS scoring but no PoC, exploit, or patch information.

    1000041
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7381 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting.

    Post summary

    The passage announces a critical vulnerability (CVE-2026-7381) in Plack::Middleware::XSendfile, detailing its CVSS score and the impact of client‑controlled path rewriting, but offers no proof‑of‑concept, exploit code, patch, or evidence of active exploitation.

    1000044
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2026-7381 · 9.1 → 1.0053 CVE: CVE-2026-7381 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists CVE-2026-7381 with a high CVSS score, but provides no evidence of exploitation, PoC, patch, or debunking, rendering it a general severity update.

    1000048
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7381-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post references CVE-2026-7381 via a URL and hashtags but does not provide concrete proof of exploitation, technical details, or mitigation information.

    0000022
    226 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7381 Client-Controlled Path Rewriting in Plack::Middleware::XSendfile Through 1.0053 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7381

    Post summary

    A brief disclosure of CVE-2026-7381 indicating a client‑controlled path rewriting flaw in Plack::Middleware::XSendfile, with no PoC, exploit, or patch information provided.

    0000031
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7381 Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (se… https://www.cve.org/CVERecord?id=CVE-2026-7381 ----- Traducción: CVE-2026-7381 Pla… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑7381, a path‑rewriting vulnerability in Plack::Middleware::XSendfile, linking to the official CVE record but providing no PoC, exploit, patch, or active exploitation details.

    0000022
    74 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7381 Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (se… https://www.cve.org/CVERecord?id=CVE-2026-7381

    Post summary

    The text announces CVE-2026-7381, describing a client‑controlled path rewriting vulnerability in Plack::Middleware::XSendfile.

    00000185
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmiyagawaplack\\--

Explore more