CVE-2026-93709

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/09/2026
Last modified:
23/09/2026

Description

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler.<br /> <br /> The handler compares the request path against the layout directory name as text, while the lookup that follows canonicalises it. A doubled slash, a dot segment, a percent-encoded slash, or a different capitalisation on a case-insensitive filesystem therefore misses the guard.<br /> <br /> The handler is off by default, enabled with auto_page. The layout wrapping every page is already public, so this discloses one of the application&amp;#39;s other layouts.