Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Debian libhttp-daemon-perl Critical Shell Command Execution DLA-4639-1

debian lts
Calendar Grey June 21, 2026
Dist Debian Esm H88
Critical flaw addressed in libhttp-daemon-perl affects Debian bullseye and bookworm with potential command execution risks.
A flaw was discovered in libhttp-daemon-perl, a simple http server class for Perl, which may result in the execution of arbitrary shell commands or file overwrite when processing s...

Summary

For Debian 11 bullseye, this problem has been fixed in version
6.12-1+deb11u2.

For Debian 12 bookworm, this problem has been fixed in version
6.16-1+deb13u1~deb12u1.

We recommend that you upgrade your libhttp-daemon-perl packages.

For the detailed security status of libhttp-daemon-perl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libhttp-daemon-perl

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libhttp-daemon-perl
Version: 6.12-1+deb11u2 6.16-1+deb13u1~deb12u1
CVE ID: CVE-2026-8450
Debian Bug: 1138050

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here