CVE-2026-93709
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/09/2026
Last modified:
23/09/2026
Description
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler.<br />
<br />
The handler compares the request path against the layout directory name as text, while the lookup that follows canonicalises it. A doubled slash, a dot segment, a percent-encoded slash, or a different capitalisation on a case-insensitive filesystem therefore misses the guard.<br />
<br />
The handler is off by default, enabled with auto_page. The layout wrapping every page is already public, so this discloses one of the application&#39;s other layouts.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/PerlDancer/Dancer2/commit/293fce08812b0928f34ab2d7b9357450707c3630.patch
- https://github.com/PerlDancer/Dancer2/commit/753b385350a54acb8d4b686723890205268634a8.patch
- https://github.com/PerlDancer/Dancer2/issues/1823
- https://metacpan.org/release/CROMEDOME/Dancer2-2.2.0/changes
- http://www.openwall.com/lists/oss-security/2026/09/22/1


