Security Advisories (1)
CVE-2026-13577 (2026-07-20)

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.

NAME

Dancer2::Template::Simple - Pure Perl 5 template engine for Dancer2

VERSION

version 0.208001

SYNOPSIS

To use this engine, you may configure Dancer2 via config.yaml:

template: simple

DESCRIPTION

This template engine is provided as a default one for the Dancer2 micro framework.

This template engine should be fine for development purposes but is not a powerful one, it's written in pure Perl and has no C bindings to accelerate the template processing.

If you want to power an application with Dancer2 in production environment, it's strongly advised to switch to Dancer2::Template::TemplateToolkit.

METHODS

render($template, \%tokens)

Renders the template. The first arg is a filename for the template file or a reference to a string that contains the template. The second arg is a hashref for the tokens that you wish to pass to Template::Toolkit for rendering.

SYNTAX

A template written for Dancer2::Template::Simple should be working just fine with Dancer2::Template::TemplateToolkit. The opposite is not true though.

variables

To interpolate a variable in the template, use the following syntax:

<% var1 %>

If var1 exists in the tokens hash given, its value will be written there.

SEE ALSO

Dancer2, Dancer2::Core::Role::Template, Dancer2::Template::TemplateToolkit.

AUTHOR

Dancer Core Developers

COPYRIGHT AND LICENSE

This software is copyright (c) 2019 by Alexis Sukrieh.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.