Security Advisories (1)
CVE-2026-13577 (2026-07-20)

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.

NAME

dancer2 - Dancer2 command line interface

VERSION

version 1.1.2

SYNOPSIS

dancer2 <command> [options...]

DESCRIPTION

Dancer2 is the new generation lightweight web-framework for Perl. This tool provides nice, easily-extendable CLI interface for it.

Documentation Index

Documentation on Dancer2 is split into several manpages. Below is a complete outline on where to go for help.

  • Dancer2 Tutorial

    If you are new to the Dancer approach, you should start by reading our Dancer2::Tutorial.

  • Dancer2 Manual

    Dancer2::Manual is the reference for Dancer2. Here you will find information on the concepts of Dancer2 application development and a comprehensive reference to the Dancer2 domain specific language.

  • Dancer2 Keywords

    The keywords for Dancer2 can be found under DSL Keywords.

  • Dancer2 Deployment

    For configuration examples of different deployment solutions involving Dancer2 and Plack, refer to Dancer2::Manual::Deployment.

  • Dancer2 Cookbook

    Specific examples of code for real-life problems and some 'tricks' for applications in Dancer can be found in Dancer2::Cookbook

  • Dancer2 Config

    For configuration file details refer to Dancer2::Config. It is a complete list of all configuration options.

  • Dancer2 Plugins

    Refer to Dancer2::Plugins for a partial list of available Dancer2 plugins. Note that although we try to keep this list up to date we expect plugin authors to tell us about new modules.

  • Dancer2 Migration guide

    Dancer2::Manual::Migration provides the most up-to-date instruction on how to convert a Dancer (1) based application to Dancer2.

NAME

dancer2 - Dancer2 command line interface

COMMANDS

  • gen

    Create a new Dancer2 application.

  • version

    Display version of Dancer2 currently installed.

To get detailed description of each individual command run:

dancer2 <command> --help

The latest list of available commands can be displayed by:

dancer2 

AUTHOR

Dancer Core Developers

COPYRIGHT AND LICENSE

This software is copyright (c) 2021 by Alexis Sukrieh.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.

AUTHOR

Dancer Core Developers

COPYRIGHT AND LICENSE

This software is copyright (c) 2024 by Alexis Sukrieh.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.