Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 96%

CVE-2026-13577: CWE-340 Generation of Predictable Numbers or Identifiers in CROMEDOME Dancer2

0
High
VulnerabilityCVE-2026-13577cvecve-2026-13577cwe-340cwe-338
Published: 07/20/2026 (07/20/2026, 07:11:10 UTC)
Source: CVE Database V5
Vendor/Project: CROMEDOME
Product: Dancer2

Description

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Affected software

GitHub Actionsmore threats →cve
Dancer2
pkg:github/Dancer2
Affected versions
<=2.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/20/2026, 08:26:56 UTC

Technical Analysis

Dancer2 versions <=2.1.0 generate session IDs using secure CSPRNG modules Math::Random::ISAAC::XS or Crypt::URandom when available. However, if these modules are missing, the generate_id function silently falls back to a weak method that derives session IDs from a SHA-1 hash of low-entropy inputs such as the built-in rand function output, module path, internal counters, process ID, memory address, and a shuffled character string. The built-in rand function is seeded with only 32 bits and is not suitable for cryptographic use, making the session IDs predictable and vulnerable to guessing attacks.

Potential Impact

Predictable session IDs can allow attackers to guess or predict valid session identifiers, potentially leading to unauthorized access to user sessions or systems relying on these session IDs for authentication or state management.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, ensure that the required CSPRNG modules (Math::Random::ISAAC::XS or Crypt::URandom) are installed and available to Dancer2 to avoid fallback to the insecure session ID generation method.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CPANSec
Date Reserved
2026-06-28T20:59:07.978Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null

Threat ID: 6a5dd8612a4a8d5989a80609

Added to database: 07/20/2026, 08:12:17 UTC

Last enriched: 07/20/2026, 08:26:56 UTC

Last updated: 07/21/2026, 00:07:25 UTC

Views: 47

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses