CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

Re: CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8521

As cited

Copy frozen at (site build).

vulnerabilities

Re: CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone

CVE-2026-85491 affects Catalyst::Seal versions before 0.03 for Perl, allowing an attacker to disable authorization checks on a path or route subsequent requests past protection by exploiting dispatch logic that relies only on the request path. The vulnerability poster clarified that repository metadata for the module contained errors.

Why it matters: Perl developers using Catalyst::Seal versions prior to 0.03 should upgrade immediately to prevent authorization bypass attacks that could allow unauthorized access to protected routes.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary