CVE-2026-8612Disclosure(oalders / www\)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache backend, WWW::Mechanize::Cached constructs a default Cache::FileCache under /tmp/FileCache without overriding the backend's documented directory_umask of 000, so the cache root and its subdirectories are created mode 0777 with no sticky bit. Cache entries are named by sha1_hex of the request and read back through Storable::thaw on the next cache hit. A local attacker with write access to the cache tree can replace a victim's cache entry for a known URL with an arbitrary frozen HTTP::Response blob, causing the victim's next get() of that URL to return attacker controlled response bytes. Because the bytes are passed to Storable::thaw, a victim process that has loaded any class with a side-effectful STORABLE_thaw, DESTROY, or overload hook can be escalated to arbitrary code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • www\

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
www\

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-15: 2Technical Details · 2026-05-15: 205-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-8500: Web::Passwd through 0.03 vulnerable to RCE https://www.openwall.com/lists/oss-security/2026/05/13/8 CVE-2026-8612: WWW::Mechanize::Cached before 2.00 deserialize HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution https://www.openwall.com/lists/oss-security/2026/05/15/1

    Post summary

    The post reports new RCE vulnerabilities in Perl modules Web::Passwd and WWW::Mechanize::Cached, detailing how deserialization and cache manipulation can lead to remote or local code execution.

    00000180
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8612 Remote Code Execution in WWW::Mechanize::Cached via Insecure Deserialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8612

    Post summary

    The note announces a remote code execution vulnerability in WWW::Mechanize::Cached due to insecure deserialization, but does not include PoC, exploit code, active exploitation evidence, or patch information.

    0000057
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoalderswww\\--

Explore more