Security Advisories (1)
CVE-2026-5091 (2026-05-21)

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

NAME

Catalyst::Plugin::Authentication::User - Compatibility shim

DESCRIPTION

THIS IS A COMPATIBILITY SHIM. It allows old configurations of Catalyst Authentication to work without code changes.

DO NOT USE IT IN ANY NEW CODE!

Please see Catalyst::Authentication::User for more information.