CVE-2026-8612

Source
https://cve.org/CVERecord?id=CVE-2026-8612
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8612.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-8612
Downstream
Published
2026-05-15T01:11:55Z
Modified
2026-08-12T03:51:27Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution
Details

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution.

With no explicit cache backend, WWW::Mechanize::Cached constructs a default Cache::FileCache under /tmp/FileCache without overriding the backend's documented directory_umask of 000, so the cache root and its subdirectories are created mode 0777 with no sticky bit. Cache entries are named by sha1_hex of the request and read back through Storable::thaw on the next cache hit.

A local attacker with write access to the cache tree can replace a victim's cache entry for a known URL with an arbitrary frozen HTTP::Response blob, causing the victim's next get() of that URL to return attacker controlled response bytes. Because the bytes are passed to Storable::thaw, a victim process that has loaded any class with a side-effectful STORABLE_thaw, DESTROY, or overload hook can be escalated to arbitrary code execution.

Database specific
{
    "cna_assigner": "CPANSec",
    "cwe_ids": [
        "CWE-502",
        "CWE-732"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8612.json"
}
References

Affected packages

Git / github.com/libwww-perl/www-mechanize-cached

Affected ranges

Type
GIT
Repo
https://github.com/libwww-perl/www-mechanize-cached
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:oalders:www\\:\\:mechanize\\:\\:cached:*:*:*:*:*:perl:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.00"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.36
v1.37
v1.38
v1.39
v1.40
v1.41
v1.42
v1.43
v1.44
v1.45
v1.46
v1.47
v1.48
v1.49
v1.50
v1.51
v1.52
v1.53
v1.54
v1.55
v1.56

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8612.json"