Skip to content
Rota Nacional

Cyber ·

CVE-2026-104380: Punk for Perl routes Extended CONNECT to any GET route without checking Origin

Security advisory from the CPAN Security Group on Punk for Perl, versions 0.48 up to before 0.55. The module may forward Extended CONNECT requests to GET routes without validating the Origin header.

Advisory CVE-2026-104380, posted to the oss-sec feed on 5 October 2026 and released by the CPAN Security Group, concerns the Punk for Perl distribution. According to the text, versions 0.48 up to before 0.55 route Extended CONNECT requests to GET routes without validating the Origin header. The source describes this behavior and the affected version range; it does not provide exploitation details or an impact assessment beyond that. To consult the full advisory, use the official CVE record and the distribution page on MetaCPAN, whose addresses appear in the original source. To verify whether your environment is affected, check whether Punk appears in your Perl project dependencies and confirm the installed version. For an organization, the relevance lies in inventorying and updating components with known flaws, not in an AI service.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free