CVE-2012-5572: Dancer

Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.

Affected products

  • Dancer Dancer: up to and including 1.3113; version 1.150 only; version 1.3060 only; version 1.3071 only; version 1.3079_3 only; version 1.3079_5 only; …

Published 2014-05-30. Last modified 2026-06-16.