Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_…
Summary
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_ID environment variable for the session id. The UNIQUE_ID variable is set by the Apache mod_unique_id plugin, which generates unique ids for the request. The id is based on the IPv4 address, the process id, the epoch time, a 16-bit counter and a thread index, with no obfuscation. The server IP is o…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://metacpan.org/pod/Apache::Session::Generate::Random
Sources
- NVD DATABASE
Original Links
- https://httpd.apache.org/docs/current/mod/mod_unique_id.html Product
- https://metacpan.org/pod/Apache::Session::Generate::Random Product
- http://www.openwall.com/lists/oss-security/2026/05/06/6 Mailing List
- https://access.redhat.com/security/cve/CVE-2026-5081
- https://bugzilla.redhat.com/show_bug.cgi?id=2467174
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5081.json
Timeline
- nvd_ingest NVD