The IO::Socket::SSL module 1.35 for Perl, when verifymode is not VERIFYNONE, fails open to VERIFYNONE instead of throwing an error when a cafile/ca_path cannot be verified, which allows remote attackers to bypass intended certificate restrictions.