CVE-2014-125112

critical
Published 2026-03-26 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-125112

vendor Authored 2026-05-27

Vendor advisory: 9b29abf9-4ab0-4765-b253-1875cd9b441e — https://metacpan.org/release/MIYAGAWA/Plack-Middleware-Session-0.23-TRIAL/changes

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.24-1
debian debianbullseyefixed0.24-1
debian debianforkyfixed0.24-1
debian debiansidfixed0.24-1
debian debiantrixiefixed0.24-1

Application impact

VendorProductVersionsFixed
miyagawaplack\{"endExcluding":"0.23"}0.23

References

CWEs

CWE-565

Verify integrity in audit chain (admin only). AS-IS.