Opened 4 months ago
Closed 4 months ago
#23327 closed enhancement (fixed)
HTTP-Daemon-6.17 (Perl module)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (10)
comment:1 by , 4 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 4 months ago
There's no Makefile.pl in this version. Build.pl wants Module-Build-Tiny, which has other deps...
comment:3 by , 4 months ago
I installed this with 'cpan -i HTTP::Daemon'.
The changes file says:
6.17 2026-05-19 23:11:06Z
- Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker- influenced input. send_file() now uses 3-arg open() with an explicit '<' read mode, so the path is always treated as a literal filename and 2-arg open() shell-magic shapes ('| cmd', 'cmd |', '> path', etc.) are no longer interpreted. send_file() now also returns '0E0' (true zero) on a successful zero-byte transfer so callers can distinguish empty file from open failure (undef). See https://www.cve.org/CVERecord?id=CVE-2026-8450 for the advisory.
comment:4 by , 4 months ago
| Owner: | changed from to |
|---|
The change explanation is a little confusing. We currently have version 6.16 in the book so I'm not sure a security advisor is needed or not.
Reassigning to SA for more analysis.
comment:5 by , 4 months ago
After some analysis I can confirm that it the vulnerability does affect 6.16, definitely a typo.
comment:6 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
Ok, so let's put the dependencies in the book. Those are:
- HTTP::Message (already in the book, with a lot of dependencies, all in the book)
- Module::Build::Tiny, which itself depends on:
- ExtUtils::Config
- ExtUtils::Helpers
- ExtUtils::InstallPaths
Other dependencies of Module::Build::Tiny are in core perl.
So we need to add 4 pages in perl-deps... Taking the ticket for now. Will give back to SecurityAdvisoriy when done
comment:8 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Dependencies added at bf5d147f23
comment:9 by , 4 months ago
| Priority: | elevated → high |
|---|
It feels weird promoting this given it's limited usage in *LFS, but the vulnerability is rated as critical on NVD, so to High it goes!

This contains a fix for CVE-2026-8450, documented as a remote code execution, arbitrary file write, and response body exfiltration vulnerability. I'm hoping for an email from the CPAN security list about this one too.