CVE-2026-97230: CWE-506 Embedded Malicious Code
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. The dropper script is in lib/Crypt/SelfCertificate/sample/cert.pem. This is similar to CVE-2026-95831 for the module Crypt::SelfCertificate. The SHA-256 digests of the files are ba24ee8ec3b7f47f65bed62e16fb413ace50653cf44bd8ea90914390922831e0 IO-Socket-SSL-SelfCertificate-1.00.tar.gz 821d38830e5eb8607738421c25ac25f59fff02a6ab67daa32fbd020429454dac IO-Socket-SSL-SelfCertificate-1.00/lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem d483cb7b23b7271cb11cf242bff4a2e1c02df0b9525eb0429abeea8961c399d5 IO-Socket-SSL-SelfCertificate-1.00-upload.tar.gz
AI Analysis
Technical Summary
The IO::Socket::SSL::SelfCertificate Perl module version 1.00 includes malware embedded in the sample certificate file (lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem). The generate_certificate function executes a Python script disguised as a certificate file. This script fetches code from a hardcoded HTTP URL, obfuscated with base64 encoding, and runs the response directly in memory. This results in arbitrary code execution under the privileges of the user running the module, without leaving persistent scripts on the system. The module lacks test scripts or build hooks, suggesting the payload triggers post-installation. The SHA-256 hashes of the affected files are provided for verification. This issue is categorized under CWE-506 (Embedded Malicious Code) and is similar to CVE-2026-95831.
Potential Impact
An attacker can execute arbitrary code on the affected system with the privileges of the user running the Perl module. The malicious code is fetched and executed dynamically from an external source without leaving persistent files, increasing stealth. This can lead to compromise of the host environment where the module is installed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using IO::Socket::SSL::SelfCertificate version 1.00 from untrusted sources. Verify the integrity of the module files using the provided SHA-256 hashes. Consider removing or replacing the affected module to prevent execution of the embedded malicious code.
CVE-2026-97230: CWE-506 Embedded Malicious Code
Description
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. The dropper script is in lib/Crypt/SelfCertificate/sample/cert.pem. This is similar to CVE-2026-95831 for the module Crypt::SelfCertificate. The SHA-256 digests of the files are ba24ee8ec3b7f47f65bed62e16fb413ace50653cf44bd8ea90914390922831e0 IO-Socket-SSL-SelfCertificate-1.00.tar.gz 821d38830e5eb8607738421c25ac25f59fff02a6ab67daa32fbd020429454dac IO-Socket-SSL-SelfCertificate-1.00/lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem d483cb7b23b7271cb11cf242bff4a2e1c02df0b9525eb0429abeea8961c399d5 IO-Socket-SSL-SelfCertificate-1.00-upload.tar.gz
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The IO::Socket::SSL::SelfCertificate Perl module version 1.00 includes malware embedded in the sample certificate file (lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem). The generate_certificate function executes a Python script disguised as a certificate file. This script fetches code from a hardcoded HTTP URL, obfuscated with base64 encoding, and runs the response directly in memory. This results in arbitrary code execution under the privileges of the user running the module, without leaving persistent scripts on the system. The module lacks test scripts or build hooks, suggesting the payload triggers post-installation. The SHA-256 hashes of the affected files are provided for verification. This issue is categorized under CWE-506 (Embedded Malicious Code) and is similar to CVE-2026-95831.
Potential Impact
An attacker can execute arbitrary code on the affected system with the privileges of the user running the Perl module. The malicious code is fetched and executed dynamically from an external source without leaving persistent files, increasing stealth. This can lead to compromise of the host environment where the module is installed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using IO::Socket::SSL::SelfCertificate version 1.00 from untrusted sources. Verify the integrity of the module files using the provided SHA-256 hashes. Consider removing or replacing the affected module to prevent execution of the embedded malicious code.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-09-24T10:09:37.672Z
- State
- PUBLISHED
Threat ID: 6ab5a8b4f7a7c54106ef034c
Added to database: 09/24/2026, 22:48:20 UTC
Last enriched: 09/24/2026, 23:02:40 UTC
Last updated: 09/25/2026, 01:55:56 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.