Junglewise Threat Intelligence

CVE-2026-95831: Crypt::SelfCertificate malware in Perl module

CVE-2026-95831 · Severity: high · CVSS 7.8 · Published 2026-09-22

Vendors: CPAN.

Executive brief

Crypt::SelfCertificate is a Perl module for generating X.509 certificates. Versions 1.01 through 1.05 contain malicious code that downloads and executes arbitrary Python payloads from a remote server when the generate_certificate function is called. An attacker can gain complete control of systems running vulnerable versions, potentially leading to data theft, malware installation, or system compromise.

Technical details

The module contains embedded Python scripts in certificate files (validate.p12 in 1.01, cert7.pem in 1.05) that execute during certificate generation. These scripts fetch obfuscated code from http://144.172.104.211/settings/privacy.php and execute it directly without validation. Attack vector is local execution when generate_certificate() is called; no authentication or network connectivity from the victim is required beyond reaching the attacker's server.

Affected products

  • CPAN Crypt::SelfCertificate 1.01 through 1.05

Timeline

  • 2026-09-22: disclosed: CPANSec identified malware in versions 1.01 and later; module removed from CPAN

References