{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-30T19:05:38.760","vulnerabilities":[{"cve":{"id":"CVE-2018-25160","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-02-27T21:16:03.590","lastModified":"2026-06-17T01:54:50.907","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend.\n\nFor example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value."},{"lang":"es","value":"Las versiones de HTTP::Session2 hasta la 1.09 para Perl no validan el formato de los ID de sesión proporcionados por el usuario, lo que permite la inyección de código u otro impacto dependiendo del backend de la sesión.\n\nPor ejemplo, si una aplicación utiliza memcached para el almacenamiento de sesiones, entonces puede ser posible para un atacante remoto inyectar comandos de memcached en el valor del ID de sesión."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"vendor":"TOKUHIROM","product":"HTTP::Session2","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"HTTP-Session2","repo":"https://github.com/tokuhirom/HTTP-Session2","versions":[{"version":"0","lessThanOrEqual":"1.09","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-03T20:22:03.246004Z","id":"CVE-2018-25160","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tokuhirom:http\\:\\:session2:*:*:*:*:*:perl:*:*","versionEndIncluding":"1.09","matchCriteriaId":"E39502F9-6512-46E9-AE15-EA57FEF5CCAE"}]}]}],"references":[{"url":"https://github.com/tokuhirom/HTTP-Session2/commit/813838f6d08034b6a265a70e53b59b941b5d3e6d.patch","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Patch"]},{"url":"https://metacpan.org/pod/Cache::Memcached::Fast::Safe","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Third Party Advisory"]},{"url":"https://metacpan.org/release/TOKUHIROM/HTTP-Session2-1.10/source/Changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Product","Release Notes"]},{"url":"http://www.openwall.com/lists/oss-security/2026/02/27/13","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]}]}}]}