Description
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources.

The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All three are predictable, low-entropy sources: the PID is drawn from a small range, the epoch time can be guessed or read from the HTTP Date header, and Perl's rand() is unsuitable for security purposes because it is predictable and reversible.

An attacker who predicts a session id can impersonate the corresponding session and bypass authentication.
Published: 2026-07-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CGI::Session::ID::md5 versions prior to 4.49 generate session identifiers by hashing the process id, the current epoch time, and Perl’s built‑in rand() function. All three components are predictable, low‑entropy sources. This weakness corresponds to CWE‑331 (Insufficient Entropy), CWE‑338 (Insufficient Randomness) and CWE‑340 (Predictable). An attacker who predicts a session id can impersonate the corresponding session and bypass authentication, compromising confidentiality and integrity of data protected by the session.

Affected Systems

The vulnerability impacts the MARKSTOS CGI::Session::ID::md5 module for Perl. Versions prior to 4.49 are affected. No specific operating system or server platform is listed, so any system running the affected module in a web context is at risk.

Risk and Exploitability

With a CVSS score of 5.9, the vulnerability presents a moderate level of risk. The EPSS score of < 1% indicates a low but nonzero probability of exploitation, yet the weakness still enables an attacker who can observe the HTTP Date header or otherwise estimate the server’s current time identifiers. The likely attack vector is remote access over HTTP/HTTPS, where an attacker can manipulate request timing or monitor session ID values. Because the epoch time, process ID, and Perl’s rand() function all have low entropy, hijacking the session and impersonating a legitimate user becomes feasible. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 21, 2026 at 14:59 UTC.

Remediation

Vendor Solution

Upgrade to CGI::Session 4.49 or later, which generates session ids from Crypt::SysRandom.


OpenCVE Recommended Actions

  • Upgrade the CGI::Session module to version 4.49 or later so that session IDs are generated using Crypt::SysRandom
  • If an upgrade cannot be performed immediately, reconfigure the application to avoid using CGI::Session::ID::md5 and instead use a more secure session ID generator or module
  • Verify that the application does not accept session IDs provided by the client for authentication or session resumption, ensuring legitimate session IDs only accepted from the server
  • Align session generation with CWE‑338 and CWE‑340 guidelines by ensuring high‑quality entropy sources are used for session ID creation

Generated by OpenCVE AI on July 21, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Markstos
Markstos cgi::session::id::md5
Vendors & Products Markstos
Markstos cgi::session::id::md5

Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-331
References
Metrics threat_severity

None

threat_severity

Important


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All three are predictable, low-entropy sources: the PID is drawn from a small range, the epoch time can be guessed or read from the HTTP Date header, and Perl's rand() is unsuitable for security purposes because it is predictable and reversible. An attacker who predicts a session id can impersonate the corresponding session and bypass authentication.
Title CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
Weaknesses CWE-338
CWE-340
References

Subscriptions

Markstos Cgi::session::id::md5
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-01T17:36:49.480Z

Reserved: 2026-06-18T11:27:09.117Z

Link: CVE-2026-56016

cve-icon Vulnrichment

Updated: 2026-07-01T17:36:49.480Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-01T06:46:23Z

Links: CVE-2026-56016 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:00:09Z

Weaknesses
  • CWE-331

    Insufficient Entropy

  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

  • CWE-340

    Generation of Predictable Numbers or Identifiers