Security Advisories (1)
CVE-2025-15604 (2026-03-28)

Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_string function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes by concatenating a SHA-1 hash seeded with the built-in rand() function, the PID, and the high resolution epoch time. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Before version 6.06, there was no fallback when /dev/urandom was not available. Before version 6.04, the random_string function used the built-in rand() function to generate a mixed-case alphanumeric string. This function may be used for generating session ids, generating secrets for signing or encrypting cookie session data and generating tokens used for Cross Site Request Forgery (CSRF) protection.

NAME

Amon2::Lite - Sinatra-ish

SYNOPSIS

use Amon2::Lite;

get '/' => sub {
    my ($c) = @_;
    return $c->render('index.tt');
};

__PACKAGE__->to_app();

__DATA__

@@ index.tt
<!doctype html>
<html>
    <body>Hello</body>
</html>

DESCRIPTION

This is a Sinatra-ish wrapper for Amon2.

THIS MODULE IS BETA STATE. API MAY CHANGE WITHOUT NOTICE.

FUNCTIONS

any(\@methods, $path, \&code)
any($path, \&code)

Register new route for router.

get($path, $code->($c))

Register new route for router.

post($path, $code->($c))

Register new route for router.

__PACKAGE__->load_plugin($name, \%opts)

Load a plugin to the context object.

__PACKAGE__->to_app()

Create new PSGI application instance.

FAQ

How can I configure the options for Xslate?

You can provide a constructor arguments by configuration. Write following lines on your app.psgi.

sub config {
    +{
        'Text::Xslate' => {
            syntax => 'Kolon'
        }
    }
}
How can I use other template engines instead of Text::Xslate?

You can use any template engine with Amon2::Lite. You can overwrite create_view method same as normal Amon2.

This is a example to use Text::MicroTemplate::File.

use Tiffany::Text::MicroTemplate::File;

sub create_view {
    Tiffany::Text::MicroTemplate::File->new(+{
        include_path => ['./tmpl/']
    })
}

AUTHOR

Tokuhiro Matsuno