Two Perl distributions, Ado::Sessions and Solstice::Session, were disclosed with vulnerabilities that generate session identifiers from weak, predictable inputs, creating a risk of session prediction and unauthorized access. In CVE-2026-5083, Ado::Sessions through version 0.935 uses a SHA-1 hash seeded with Perl rand, epoch time, and process ID; in CVE-2026-5085, Solstice::Session through version 1440 uses an MD5 digest built from epoch time, a stringified hash reference, Perl rand(), and process ID, with the same pattern also affecting Solstice::Subsession via _generateID.
Both flaws were classified under CWE-340 and CWE-338, reflecting predictable values and insufficient entropy in security-sensitive randomness. The disclosures warn that attackers may be able to infer or guess the underlying inputs—particularly time and PID values—and derive valid session tokens to hijack active sessions. The Ado issue is compounded by the project’s abandoned status: the distribution is no longer maintained, has been removed from the CPAN index, and remains available only on BackPAN.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The CPAN Security Group disclosed CVE-2026-5084 on oss-sec, affecting WebDyne::Session through version 2.075 due to predictable session ID generation based on an MD5 hash seeded with Perl's rand() and related weak inputs. The advisory warned that attackers could potentially predict session identifiers and gain unauthorized access to affected systems.
The CPAN Security Group disclosed CVE-2026-5085 on oss-sec, affecting Solstice::Session through version 1440 and Solstice::Subsession due to predictable session ID generation using weak inputs such as time, rand(), and PID.
A notice was issued stating that the Ado project would no longer receive updates. The advisory later notes the project is unmaintained and removed from the CPAN index.
The last Ado release on CPAN, version 0.935, was published. This version is later identified as affected by insecure session ID generation in Ado::Sessions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.