Security Advisories (4)
CPANSA-Plack-2015-0202 (2015-02-02)

Fixed a possible directory traversal with Plack::App::File on Win32.

CPANSA-Plack-2014-0801 (2014-08-01)

Plack::App::File would previously strip trailing slashes off provided paths. This in combination with the common pattern of serving files with Plack::Middleware::Static could allow an attacker to bypass a whitelist of generated files

CPANSA-Plack-2013-0131 (2013-01-31)

Fixed directory traversal bug in Plack::App::File on win32 environments

CVE-2026-7381 (2026-04-29)

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the "X-Accel-Redirect" type.

NAME

Plack::App::FCGIDispatcher - Dispatch requests to FCGI servers

SYNOPSIS

# app.psgi
use Plack::App::FCGIDispatcher;
my $app = Plack::App::FCGIDispatcher->new({
    port => 8080, # FastCGI daemon port
})->to_app;

DESCRIPTION

Plack::App::FCGIDispatcher is a PSGI application to dispatch requests to external FastCGI servers listening on TCP or UNIX sockets.

Since external FastCGI servers can be written in any language such as Ruby or PHP, this could be useful to route requests to Rails applications for instance from your Plack-based web server, or apply one of Plack middleware to PHP applications.

See also Plack::App::Proxy which uses HTTP instead of FastCGI and has more configuration options.

CONFIGURATION

host, port
my $app = Plack::App::FCGIDispatcher->new({
    host => '127.0.0.1', port => 8080,
})->to_app;

Specifies host and port where FastCGI daemon is listening. host defaults to 127.0.0.1.

socket
my $app = Plack::App::FCGIDispatcher->new({
    socket => "/tmp/fcgi.sock",
})->to_app;

Specifies UNIX socket path where FastCGI daemon is listening.

AUTHOR

Tokuhiro Matsuno

Tatsuhiko Miyagawa

SEE ALSO

FCGI::Client