Security Advisories (1)
CVE-2026-13577 (2026-07-20)

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.

NAME

Dancer2::Core::Types - Type::Tiny types for Dancer2 core.

VERSION

version 2.1.0

DESCRIPTION

Type::Tiny definitions for Moo attributes. These are defined as subroutines.

MOO TYPES

ReadableFilePath($value)

A readable file path.

WritableFilePath($value)

A writable file path.

Dancer2Prefix($value)

A proper Dancer2 prefix, which is basically a prefix that starts with a / character.

Dancer2AppName($value)

A proper Dancer2 application name.

Currently this only checks for \w+.

Dancer2Method($value)

An acceptable method supported by Dancer2.

Currently this includes: get, head, post, put, delete and options.

Dancer2HTTPMethod($value)

An acceptable HTTP method supported by Dancer2.

Current this includes: GET, HEAD, POST, PUT, DELETE and OPTIONS.

SEE ALSO

Types::Standard for more available types

AUTHOR

Dancer Core Developers

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Alexis Sukrieh.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.