Apache::Session versions through 1.94 for Perl re-creates...
Critical severity
Unreviewed
Published
May 8, 2026
to the GitHub Advisory Database
•
Updated May 8, 2026
Description
Published by the National Vulnerability Database
May 8, 2026
Published to the GitHub Advisory Database
May 8, 2026
Last updated
May 8, 2026
Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
References