Alerts This Week
Warning Icon 1 357
Alerts This Week
Warning Icon 1 357

Fedora 44 perl-Catalyst-Plugin-Authentication Vulnerability CVE-2026-5091

fedora
Calendar Grey June 1, 2026
Dist Fedora Esm H88
Catalyst::Plugin::Authentication for Fedora 44 fixes timing attack issues in versions up to 0.10024. Upgrade recommended.
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl's built-in eq comparison

Summary

The authentication plugin provides generic user support for Catalyst apps.

It is the basis for both authentication (checking the user is who they

claim to be), and authorization (allowing the user to do what the system

authorizes them to do).

Update Information:

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.

Change Log

* Sun May 24 2026 Emmanuel Seyman - 0.10026-1 - Update to 0.10026 (fixes CVE-2026-5091)

References


[ 1 ] Bug #2483712 - CVE-2026-5091 perl-Catalyst-Plugin-Authentication: Catalyst::Plugin::Authentication: Information disclosure via timing attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483712

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-26666575ae' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: perl-Catalyst-Plugin-Authentication
Product: Fedora 44
Version: 0.10026
Release: 1.fc44
Summary: Infrastructure plugin for the Catalyst authentication framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here