Debian Package Tracker
Register | Log in
Subscribe

libdancer2-perl

lightweight yet powerful web application framework

Choose email to subscribe with

general
  • source: libdancer2-perl (main)
  • version: 2.2.2-1
  • maintainer: Debian Perl Group (archive) (DMD) (LowNMU)
  • uploaders: gregor herrmann [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.300005+dfsg-1
  • oldstable: 0.400001+dfsg-1
  • stable: 1.1.2+dfsg-1
  • testing: 2.2.2-1
  • unstable: 2.2.2-1
versioned links
  • 0.300005+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.400001+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.1.2+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.2.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libdancer2-perl
action needed
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-13577: Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.
Created: 2026-07-20 Last update: 2026-08-09 01:33
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2026-13577: (needs triaging) Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.
  • CVE-2026-93711: (needs triaging) Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the PSGI server intact. A server that does not validate keys writes it to the wire, so the bytes after the CRLF arrive as their own header line. The application has to derive the header name from request data, not just the value. An attacker who controls that data adds their own headers and splits the response.
  • CVE-2026-93712: (needs triaging) Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and checks only that the result is a readable regular file. A request for `/../outside.txt` escapes public_dir, and percent-encoding the dots reaches the same file. The handler is off by default. An application is affected once it names File in route_handlers and sets static_handler to 0, which otherwise refuses a dot segment before the route runs. Any file the worker process can read is served to an unauthenticated request, including the application's config.yml above public_dir.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-20 Last update: 2026-10-04 18:31
news
[rss feed]
  • [2026-09-29] Accepted libdancer2-perl 2.2.2-1 (source) into unstable (gregor herrmann)
  • [2026-04-08] libdancer2-perl 2.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-06] Accepted libdancer2-perl 2.1.0-1 (source) into unstable (gregor herrmann)
  • [2026-02-24] libdancer2-perl 2.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-21] Accepted libdancer2-perl 2.0.1-1 (source) into unstable (gregor herrmann)
  • [2024-12-10] libdancer2-perl 1.1.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-08] Accepted libdancer2-perl 1.1.2+dfsg-1 (source) into unstable (gregor herrmann)
  • [2024-07-31] libdancer2-perl 1.1.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-28] Accepted libdancer2-perl 1.1.1+dfsg-1 (source) into unstable (gregor herrmann)
  • [2023-12-18] libdancer2-perl 1.1.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-18] libdancer2-perl 1.1.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-15] Accepted libdancer2-perl 1.1.0+dfsg-1 (source) into unstable (gregor herrmann)
  • [2023-11-06] libdancer2-perl 1.0.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-03] Accepted libdancer2-perl 1.0.0+dfsg-1 (source) into unstable (gregor herrmann)
  • [2023-02-13] libdancer2-perl 0.400001+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-10] Accepted libdancer2-perl 0.400001+dfsg-1 (source) into unstable (gregor herrmann)
  • [2022-04-12] libdancer2-perl 0.400000+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-09] Accepted libdancer2-perl 0.400000+dfsg-1 (source) into unstable (gregor herrmann)
  • [2021-10-25] libdancer2-perl 0.301004+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-23] Accepted libdancer2-perl 0.301004+dfsg-1 (source) into unstable (gregor herrmann)
  • [2021-04-03] libdancer2-perl 0.300005+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-03-13] Accepted libdancer2-perl 0.300005+dfsg-1 (source) into unstable (gregor herrmann)
  • [2020-06-16] libdancer2-perl 0.300004+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2020-06-13] Accepted libdancer2-perl 0.300004+dfsg-2 (source) into unstable (gregor herrmann)
  • [2020-06-01] libdancer2-perl 0.300004+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-29] Accepted libdancer2-perl 0.300004+dfsg-1 (source) into unstable (gregor herrmann)
  • [2020-04-13] libdancer2-perl 0.300003+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-04-10] Accepted libdancer2-perl 0.300003+dfsg-1 (source) into unstable (gregor herrmann)
  • [2020-04-10] libdancer2-perl 0.300001+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-04-06] Accepted libdancer2-perl 0.300001+dfsg-1 (source) into unstable (gregor herrmann)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.1.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing