Security Advisories (4)
CPANSA-Plack-2015-0202 (2015-02-02)

Fixed a possible directory traversal with Plack::App::File on Win32.

CPANSA-Plack-2014-0801 (2014-08-01)

Plack::App::File would previously strip trailing slashes off provided paths. This in combination with the common pattern of serving files with Plack::Middleware::Static could allow an attacker to bypass a whitelist of generated files

CPANSA-Plack-2013-0131 (2013-01-31)

Fixed directory traversal bug in Plack::App::File on win32 environments

CVE-2026-7381 (2026-04-29)

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the "X-Accel-Redirect" type.

NAME

Plack::Middleware::Static - serve static files with Plack

SYNOPSIS

use Plack::Builder;

builder {
    enable "Plack::Middleware::Static",
        path => qr{^/(images|js|css)/}, root => './htdocs/';
    $app;
};

DESCRIPTION

Enable this middleware to allow your Plack-based application to serve static files. If a static file exists for the requested path, it will be served. Otherwise, the request will be passed on to the application for further processing.

If the requested document is not within the root (i.e. directory traversal) or the file is there but not readable, this middleware will return a 403 Forbidden response.

The content type returned will be determined from the file extension based on Plack::MIME.

CONFIGURATIONS

path, root
enable "Plack::Middleware::Static",
    path => qr{^/static/}, root => 'htdocs/';

path specifies the URL pattern (regular expression) or a callback to match with requests to serve static files for. root specifies the root directory to serve those static files from. The default value of root is the current directory.

This examples configuration serves /static/foo.jpg from htdocs/static/foo.jpg. Note that the matched /static/ portion is still appears in the local mapped path. If you don't like it, use a callback instead to munge $_:

enable "Plack::Middleware::Static",
    path => sub { s!^/static/!! }, root => 'static-files/';

This configuration would serve /static/foo.png from static-files/foo.png (not static-files/static/foo.png). The callback specified in path option matches against $_ and then updates the value since it does s///, and returns the number of matches, so it will pass through when /static/ doesn't match.

If you want to map multiple static directories from different root, simply add "this", middleware multiple times with different configuration options.

AUTHOR

Tokuhiro Matsuno, Tatsuhiko Miyagawa

SEE ALSO

Plack::Middleware Plack::Builder