Junglewise Threat Intelligence

CVE-2026-93710: Dancer2 route dispatch bypass in hook exception handling

CVE-2026-93710 · Severity: high · CVSS 7.5 · Published 2026-09-22

Executive brief

Dancer2 is a web framework for Perl applications. A flaw in how it handles exceptions thrown by before-request hooks allows a refused route to execute anyway if the exception handler halts the response, potentially causing unintended side effects like database changes, charges, or emails sent by that route.

Technical details

A dying before hook triggers the core.app.hook_exception handler, but if that handler halts the response without stopping cleanup, the dispatcher reads a fresh response object that is not halted and dispatches to the refused route. The vulnerability exists in Dancer2 versions 2.0.0 to 2.1.x in the compile_hooks method of lib/Dancer2/Core/App.pm; the fix skips cleanup when a halted response is present, ensuring the halted state survives for the dispatcher to read.

Affected products

  • Dancer2 Project Dancer2 2.0.0 to before 2.2.0

Timeline

  • 2026-09-22: disclosed
  • 2026-08-05: patched

References