Junglewise Threat Intelligence

CVE-2026-13577: Dancer2 insecure session ID generation in SessionFactory

CVE-2026-13577 · Severity: info · CVSS 0 · Published 2026-07-20

Executive brief

Dancer2 is a popular web application framework for the Perl programming language. A security issue exists where the framework may generate predictable session identifiers if certain security-related software components are missing from the server. An attacker who can guess these identifiers could hijack user sessions, potentially gaining unauthorized access to sensitive data or administrative functions.

Technical details

Dancer2::Core::Role::SessionFactory::generate_id contains a fallback mechanism that triggers when Math::Random::ISAAC::XS and Crypt::URandom are unavailable. In this scenario, the framework silently reverts to using the built-in Perl rand() function, which is seeded with only 32-bits of entropy. The resulting session ID is a SHA-1 hash of low-entropy sources including the process ID, memory addresses, and an internal counter. A remote attacker could potentially predict these session IDs to perform session fixation or hijacking attacks. The vulnerability is classified under CWE-338 (Use of Cryptographically Weak PRNG).

Affected products

  • CROMEDOME Dancer2 through 2.1.0

Timeline

  • 2026-07-20: advisory: NVD publication date

References