Executive brief
Dancer2 is a web framework for Perl applications. A flaw in how it handles exceptions thrown by before-request hooks allows a refused route to execute anyway if the exception handler halts the response, potentially causing unintended side effects like database changes, charges, or emails sent by that route.
Technical details
A dying before hook triggers the core.app.hook_exception handler, but if that handler halts the response without stopping cleanup, the dispatcher reads a fresh response object that is not halted and dispatches to the refused route. The vulnerability exists in Dancer2 versions 2.0.0 to 2.1.x in the compile_hooks method of lib/Dancer2/Core/App.pm; the fix skips cleanup when a halted response is present, ensuring the halted state survives for the dispatcher to read.
Affected products
- Dancer2 Project Dancer2 2.0.0 to before 2.2.0
Timeline
- 2026-09-22: disclosed
- 2026-08-05: patched