
Perl CPAN CVE-2026-8500: Web::Passwd through 0.03 vulnerable to RCE https://www.openwall.com/lists/oss-security/2026/05/13/8 CVE-2026-8612: WWW::Mechanize::Cached before 2.00 deserialize HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution https://www.openwall.com/lists/oss-security/2026/05/15/1
Post summary
The post reports new RCE vulnerabilities in Perl modules Web::Passwd and WWW::Mechanize::Cached, detailing how deserialization and cache manipulation can lead to remote or local code execution.

