CVE-2026-85491: authorization flaw in Catalyst::Seal
A notice published on September 24, 2026 says versions of Catalyst-Seal earlier than 0.03 may let one request affect another request’s authorization or routing.
The notice identifies CVE-2026-85491 in the Catalyst-Seal package. Published on September 24, 2026, it says versions earlier than 0.03 are affected.
The description points to a dispatch memory indexed only by the request path. In that situation, one request may affect the authorization or routing of another.
To assess exposure, check the installed version against the range stated in the notice. Do not assume a version is affected without confirming the package identity and the version actually in use.
Consult the original oss-sec feed notice and Catalyst-Seal package metadata to confirm the scope and check for updates. If you use AI to analyze logs or study a fix, apply your organization’s personal-data policy and avoid submitting credentials or unnecessary sensitive information.