Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-95831

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/09/2026
Última modificación:
23/09/2026

Descripción

*** Pendiente de traducción *** Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL.<br /> <br /> The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.<br /> <br /> The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.<br /> <br /> The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation.<br /> <br /> For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12.<br /> <br /> For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem.<br /> <br /> The SHA-256 digests of the files are<br /> <br /> fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz<br /> 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12<br /> <br /> 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz<br /> 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem