What is CVE-2026-17435?
CVE-2026-17435 affects File::Rotate::Simple for Perl versions before 0.4.0, where dangling symlink targets are created due to a flaw in the file existence check when the 'touch' option is enabled. This can lead to unintended file creation, posing a potential security risk. Users should upgrade to version 0.4.0 or later to mitigate the issue.
Azərbaycanca: CVE-2026-17435 boşluqda qalan simvolik keçidlərin hədəf fayllarını yaradan Perl üçün File::Rotate::Simple modulunun 0.4.0-dan əvvəlki versiyalarına təsir edir. `touch` seçimi aktiv olduqda fayl yoxlama mexanizmindəki qüsur səbəbindən gözlənilməz fayl yaradılması baş verə bilər, bu da potensial təhlükəsizlik riski yaradır. Təsirlənmiş istifadəçilər modulu 0.4.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which component is affected by CVE-2026-17435?
The vulnerability affects File::Rotate::Simple for Perl versions before 0.4.0.
What should be done to fix CVE-2026-17435?
Users should upgrade the File::Rotate::Simple module to version 0.4.0 or later to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.