Skip to content

CVE-2026-104380: routing flaw in Punk for Perl

Advisory published on the oss-sec mailing list on October 5, 2026: Punk for Perl versions 0.48 through releases before 0.55 may route Extended CONNECT to GET routes without validating Origin.

By Wendelmaques ·

Source: CVE-2026-104380: Punk para Perl roteia Extended CONNECT para qualquer rota GET sem verificar Origin (seclists.org). Text prepared with AI from this source.

What happened and what to do

The advisory published on the oss-sec mailing list on October 5, 2026 describes CVE-2026-104380 in Punk for Perl. Versions 0.48 through releases before 0.55 may route Extended CONNECT requests to GET routes without checking the Origin header.

Companies using these versions can inventory dependencies, identify exposed services, update Punk to a fixed release, and test routing and Origin validation. An automated dependency-monitoring process can flag vulnerable versions and track remediation across environments.

How the consultancy can help

Wendelmaques can diagnose exposure across systems and dependencies, define a clearly scoped remediation, and implement tests and monitoring to track upgrades and route validation.

Next step

Send a short description of your environment and case to receive a scoped proposal.

Consulting for your project

Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.

Quoted per project

Request a proposal

Looking for something else?Frequently asked questionsArticlesContact