This update has improvements to generate more secure session IDs (CVE-2026-8503).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-19d80281b7 2026-05-23 00:56:16.173336+00:00 -------------------------------------------------------------------------------- Name : perl-Apache-Session-Browseable Product : Fedora 44 Version : 1.3.19 Release : 1.fc44 URL : https://metacpan.org/release/Apache-Session-Browseable Summary : Add index and search methods to Apache::Session Description : A virtual Apache::Session back-end providing some class methods to manipulate all sessions and add the capability to index some fields to make re-search faster. -------------------------------------------------------------------------------- Update Information: This update has improvements to generate more secure session IDs (CVE-2026-8503). -------------------------------------------------------------------------------- ChangeLog: * Thu May 14 2026 Paul Howarth - 1.3.19-1 - Update to 1.3.19 (rhbz#2477392) - Apache::Session::Generate::SHA256 used a low-entropy seed (time, PID, rand, stringified hash ref) to derive session identifiers; use Crypt::URandom to generate session ids from a cryptographically secure source, falling back to the previous hashing method only if Crypt::URandom is unavailable (CVE-2026-8503, similar in scope to CVE-2025-40931 and CVE-2025-40932) - Fix Redis indexes: never cleaned before - Improve resilience and reliability of Patroni driver * Thu Apr 9 2026 Xavier Bachelot - 1.3.18-4 - BR: perl(DBD::Cassandra) to improve test coverage -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477392 - perl-Apache-Session-Browseable-1.3.19 is available https://bugzilla.redhat.com/show_bug.cgi?id=2477392 [ 2 ] Bug #2477847 - CVE-2026-8503 perl-Apache-Session-Browseable:perl-Apache-Session-Browseable: Predictable session IDs allow unauthorized system access [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477847 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-19d80281b7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.