Security Advisories (1)
CVE-2026-75870 (2026-08-22)

Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is absent. The cookie read and the write-back both default that key to the empty string, so a declaration with no secret option, or with an undefined or empty one, signs and verifies with a zero-length HMAC-SHA256 key. An attacker who knows the cookie format can then mint one offline carrying any contents the session holds, such as a user identifier or a role. Nothing marks the misconfiguration at runtime: cookies are well formed and sessions round-trip as expected.

Changes for version 0.10 - 2026-08-15

  • Development error pages (Punk::DevError): in development a die renders an HTML debug page
  • The environment now defaults to production; development is an opt-in: punk dev sets PUNK_ENV=development for its server, or set it yourself in the Env.
  • Punk::Validate: request validation, all in C on the JSON::Schema::Fast C ABI. $c->validate($schema) collects into a Result - errors in the Open::API shape plus name, valid() hands back typed filtered params - and a bare $c->validate reads the Result a route-level check stashed. Routes take an options hashref: get '/x' => $target, { validate => \%schema } (or { schema, source, on_invalid }), compiled once at to_app and run as a C guard after any auth guards; failures answer the OpenAPI-mount-shaped 400 or the on_invalid target.
  • New on_not_found keyword: the on_error contract for a 404 so you can return a custom response
  • The getentropy probe now links instead of only compiling. FreeBSD before 12 has no getentropy and its old compilers take the implicit declaration as a warning, so 0.09's compile-only probe false-positived and the .so failed to load with "Undefined symbol getentropy".

Modules

a MVC web framework
the per-application registry and boot compiler
cross-origin resource sharing
single-use CSRF tokens
the subcommands behind the punk tool
YAML configuration with secrets kept out of the file
the per-request object
base class for Punk controllers
the development error page
an async result that runs on the loop, or blocks
scaffold a new Punk application
a level-based logger
the storage-agnostic model tier
the default DBI backend for Punk models
a non-blocking backend for Punk models
a directory of markdown as a documentation site
the api mount: spec-first operations
base class for Punk plugins
rate limiting and IP blocking over Hyperman's shared arena
a lazy wrapper over the PSGI environment
a response builder
the compiled-at-boot route tables (XS)
the handle an under returns
a Server-Sent Events stream
signed cookie sessions
serving files from a directory
an in-process test client for Punk applications
a pure-Perl RFC 6455 codec for testing WebSocket servers
the client side of one WebSocket connection
the outbound HTTP agent on the context
an uploaded file from a multipart form
collecting request validation
the Template::Stencil view engine
the pluggable view engine registry (XS)
a WebSocket connection
pub/sub groups of WebSocket connections

Provides

in bench/apps/cat-lib/BenchCat.pm
in bench/apps/cat-lib/BenchCat/Controller/Root.pm
in lib/Punk/Test.pm