Security Advisories (1)
CVE-2026-104380 (2026-10-06)

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.

NAME

Punk::DBI::st - the observed statement handle

DESCRIPTION

The statement-handle half of Punk::DBI: execute, so a pk_abi query observer sees a statement the caller prepared and drove itself. This is the path Punk::Model::DBI's generated methods take, through prepare_cached.

The SQL comes from $sth->{Statement} - what was prepared, placeholders and all - and the bind count from the argument list. The values are never passed on.

prepare_cached is unaffected: the subclass changes the class of the handle, not its caching, and one statement handle per distinct SQL string is still what a connection holds.

SEE ALSO

Punk::DBI, Punk::DBI::db.

AUTHOR

LNATION <email@lnation.org>

LICENSE AND COPYRIGHT

This software is Copyright (c) 2026 by LNATION <email@lnation.org>.

This is free software, licensed under:

The Artistic License 2.0 (GPL Compatible)