What is CVE-2026-17552?
CVE-2026-17552: A vulnerability in Plack::App::Prerender versions before 0.3.0 for Perl allows proxying to an arbitrary host due to unsafe concatenation of REQUEST_URI when the rewrite base is a plain string. Affected users should upgrade to version 0.3.0 or later immediately.
Azərbaycanca: CVE-2026-17552: Plack::App::Prerender-in 0.3.0-dan əvvəlki versiyalarında REQUEST_URI-nin təhlükəsiz şəkildə birləşdirilməməsi səbəbindən ixtiyari host-a proksi etməyə imkan verən zəiflik aşkarlanıb. Bu, "rewrite base" sadə mətn olduqda baş verir. Təsirə məruz qalan istifadəçilər dərhal 0.3.0 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Plack::App::Prerender are affected by CVE-2026-17552?
Versions of Plack::App::Prerender before 0.3.0 are affected.
What is the root cause of CVE-2026-17552?
Unsafe concatenation of REQUEST_URI when the rewrite base is a plain string, allowing proxying to an arbitrary host.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.