CVE-2026-8450: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in OALDERS HTTP::Daemon
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
AI Analysis
Technical Summary
HTTP::Daemon versions prior to 6.17 for Perl contain an OS command injection vulnerability in the send_file() method. This method uses Perl's 2-argument open() function, which interprets special prefixes such as '| cmd' or 'cmd |' to open pipes to subprocesses, and '> path' or '>> path' to open files for writing or appending. If untrusted input is passed to send_file(), an attacker can execute arbitrary OS commands with the daemon process's user ID. Additionally, the read-pipe form can leak subprocess stdout into HTTP responses, and the write-mode forms can create or truncate files at attacker-controlled paths. This vulnerability is tracked as CVE-2026-8450 with a CVSS score of 9.1 (critical). Red Hat has released security updates for affected packages in Red Hat Enterprise Linux 10 and related products.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary OS commands with the privileges of the HTTP::Daemon process user. This can lead to full compromise of the affected system, including unauthorized disclosure of subprocess output via HTTP responses and unauthorized file creation or modification. The vulnerability has a CVSS v3.1 base score of 9.1, indicating high confidentiality and integrity impact with no required privileges or user interaction.
Mitigation Recommendations
Red Hat has released security updates addressing this vulnerability in perl-HTTP-Daemon packages for Red Hat Enterprise Linux 10 and related distributions. Users should apply these official patches promptly. Refer to Red Hat advisory RHSA-2026:36189 and https://access.redhat.com/articles/11258 for update instructions. No alternative mitigations are specified; applying the vendor-provided update is required to remediate the issue.
CVE-2026-8450: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in OALDERS HTTP::Daemon
Description
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
CVSS v3.1
Score 9.1critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
HTTP::Daemon versions prior to 6.17 for Perl contain an OS command injection vulnerability in the send_file() method. This method uses Perl's 2-argument open() function, which interprets special prefixes such as '| cmd' or 'cmd |' to open pipes to subprocesses, and '> path' or '>> path' to open files for writing or appending. If untrusted input is passed to send_file(), an attacker can execute arbitrary OS commands with the daemon process's user ID. Additionally, the read-pipe form can leak subprocess stdout into HTTP responses, and the write-mode forms can create or truncate files at attacker-controlled paths. This vulnerability is tracked as CVE-2026-8450 with a CVSS score of 9.1 (critical). Red Hat has released security updates for affected packages in Red Hat Enterprise Linux 10 and related products.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary OS commands with the privileges of the HTTP::Daemon process user. This can lead to full compromise of the affected system, including unauthorized disclosure of subprocess output via HTTP responses and unauthorized file creation or modification. The vulnerability has a CVSS v3.1 base score of 9.1, indicating high confidentiality and integrity impact with no required privileges or user interaction.
Mitigation Recommendations
Red Hat has released security updates addressing this vulnerability in perl-HTTP-Daemon packages for Red Hat Enterprise Linux 10 and related distributions. Users should apply these official patches promptly. Refer to Red Hat advisory RHSA-2026:36189 and https://access.redhat.com/articles/11258 for update instructions. No alternative mitigations are specified; applying the vendor-provided update is required to remediate the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-05-12T21:26:04.212Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-8450","vendor":"Red Hat"}]
Threat ID: 6a167b26e29bf47b509852a7
Added to database: 05/27/2026, 05:03:34 UTC
Last enriched: 07/16/2026, 09:13:34 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 141
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.