CVE-2026-5091: Jjnapiork Catalyst::plugin::authentication
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.
Affected products
- Jjnapiork Catalyst::plugin::authentication: up to and including 0.10024
Published 2026-05-21. Last modified 2026-07-23.