CYBERSECURITYTRACKER
TRACKING7,353 stories in this site build1,545 vulnerability news stories in this site build
Permanent story citation

CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8101

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler

Dancer2, a Perl web framework, contains a vulnerability in its AutoPage handler that allows serving layout files as pages when path variants bypass the guard mechanism. Affected versions are before 2.2.0. The issue enables unintended access to protected template content through alternate path spellings.

Why it matters: Developers using Dancer2 before version 2.2.0 should upgrade immediately to prevent attackers from accessing layout files and potentially sensitive templating logic through path manipulation.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary