TOKUHIROM Vulnerabilities and Affected Products
Vulnerabilities associated with Amon2::Plugin::Web::CSRFDefender.
Products
Clear product- HTTP::Session22 vulnerabilities
- Amon21 vulnerability
- Amon2::Plugin::Web::CSRFDefender1 vulnerability
- Image::EPEG1 vulnerability
- UnQLite1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-5082MEDIUM | Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session idAmon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes using SHA-1 hash seeded with the built-in rand() function, the PID, and the high resolution epoch time. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand… | CVSS5.3v3.1 | EPSS0.405% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |