CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6048

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step

CVE-2026-86219 affects Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100, allowing attackers to replay authentication responses because the server_step function fails to verify the nonce. This cryptographic weakness in the Perl SASL library undermines the security of Digest MD5 authentication mechanisms.

Why it matters: Perl applications using Authen-SASL for DIGEST_MD5 authentication require immediate update to version 2.2100 or later to prevent attackers from bypassing authentication controls with captured credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step

CVE-2026-86219 affects Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100, allowing attackers to replay authentication responses because the server_step function fails to verify the nonce. This cryptographic weakness in the Perl SASL library undermines the security of Digest MD5 authentication mechanisms.

Why it matters: Perl applications using Authen-SASL for DIGEST_MD5 authentication require immediate update to version 2.2100 or later to prevent attackers from bypassing authentication controls with captured credentials.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary