Security Advisories (4)
CVE-2026-7381 (2026-04-29)

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the "X-Accel-Redirect" type.

CPANSA-Plack-2015-0202 (2015-02-02)

Fixed a possible directory traversal with Plack::App::File on Win32.

CPANSA-Plack-2014-0801 (2014-08-01)

Plack::App::File would previously strip trailing slashes off provided paths. This in combination with the common pattern of serving files with Plack::Middleware::Static could allow an attacker to bypass a whitelist of generated files

CPANSA-Plack-2013-0131 (2013-01-31)

Fixed directory traversal bug in Plack::App::File on win32 environments

NAME

Plack::Middleware::HTTPExceptions - Catch HTTP exceptions

SYNOPSIS

use HTTP::Exception;

my $app = sub {
    # ...
    HTTP::Exception::500->throw;
};

builder {
    enable "HTTPExceptions";
    $app;
};

DESCRIPTION

Plack::Middleware::HTTPExceptions is a PSGI middleware component to catch exceptions from applicaitions that can be translated into HTTP status code.

Your application is supposed to throw an object that implements code method which returns the HTTP status code such as 501 or 404. This middleware catches them and creates a valid response out of the code.

The exception object may also implement as_string, or overload the stringification, to represent the text of the error, which defaults to the status message of error codes, such as Service Unavailable for 503.

If the code is in the 3xx range and the exception implements the 'location' method (HTTP::Exception::3xx does), the Location header will be set in the response, so you can do redirects this way.

There's a CPAN module HTTP::Exception and they are pefect to throw from your application to let this middleware catch and display, but you can also implement your own exception class to throw.

All the other errors that can't be translated into HTTP errors are just rethrown to the outer frame.

AUTHOR

Tatsuhiko Miyagawa

SEE ALSO

paste.httpexceptions HTTP::Exception