Junglewise Threat Intelligence

CVE-2026-5087: JJNAPIORK PAGI::Middleware::Session::Store::Cookie weak PRNG in IV generation

CVE-2026-5087 · Severity: high · CVSS 7.5 · Published 2026-03-31

Executive brief

A Perl module used for managing web session cookies contains a security flaw in how it handles encryption. On certain systems, such as Windows, the software uses a weak method to generate security keys, making it possible for attackers to predict those keys. This could allow a malicious user to decrypt or tamper with session data, potentially leading to unauthorized access or data manipulation.

Technical details

The PAGI::Middleware::Session::Store::Cookie module (versions up to 0.001003) fails to securely generate random bytes when the /dev/urandom device is missing, such as on Windows environments. In these cases, the module falls back to the built-in Perl 'rand' function, which is a cryptographically weak pseudo-random number generator (PRNG). These weak random bytes are used as Initialization Vectors (IVs) for cookie encryption. An attacker can exploit this predictability to decrypt or modify session cookies. The issue is addressed in version 0.001004.

Affected products

  • JJNAPIORK PAGI::Middleware::Session::Store::Cookie through 0.001003

Timeline

  • 2026-03-31: disclosed
  • 2026-03-31: advisory
  • 2026-03-31: patched: Fixed in version 0.001004

References