Security Advisories (1)
CVE-2026-7381 (2026-04-29)

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the "X-Accel-Redirect" type.

NAME

Plack::Test::Suite - Test suite for Plack handlers

SYNOPSIS

use Test::More;
use Plack::Test::Suite;
Plack::Test::Suite->run_server_tests('Your::Handler');
done_testing;

DESCRIPTION

Plack::Test::Suite is a test suite to test a new PSGI server implementation. It automatically loads a new handler environment and uses LWP to send HTTP requests to the local server to make sure your handler implements the PSGI specification correctly.

Note that the handler name doesn't include the Plack::Handler:: prefix, i.e. if you have a new Plack handler Plack::Handler::Foo, your test script would look like:

Plack::Test::Suite->run_server_tests('Foo');

Developers writing Plack applications should look at Plack::Test for testing, as subclassing Plack::Handler is for developing server implementations.

AUTHOR

Tokuhiro Matsuno

Tatsuhiko Miyagawa

Kazuho Oku