Security Advisories (1)
CVE-2026-9658 (2026-05-28)

Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header injections in the request paths unless they were double-encoded, for example, GET /path\r\nHTTP/1.1\r\nHost: secret.example.com Note that it is unclear whether request paths with CRLF followed by additional headers would be blocked by reverse proxies, or how they would be processed by Plack-based servers.

Changes for version v0.4.1 - 2020-03-11

  • Enhancements
    • Simplify unexpected_content rule.
    • New rule: require_content.
    • Updated rule: cgi_bin to incldue cgi_wrapper.
    • Updated rule: dot_files to include "../" in path or query string.
    • The HTTP status can be overridden without overriding the handler.
    • The log message includes the request method and HTTP status.
  • Documentation
    • Fixed POD formatting.
    • Documented the format of the log message.
    • Added note about modsecurity.

Documentation

Modules

A simple security filter for with common rules.
A simple security filter for Plack