HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().
send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append.
Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade perl-HTTP-Daemon | Jul 7, 2026 | Jul 7, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-HTTP-Daemon | Jun 9, 2026 | Jun 9, 2026 |
| Debian | — | Upgrade libhttp-daemon-perl | Jun 22, 2026 | Jun 22, 2026 |
| Redhat_linux | — | No solution existsUpgrade perl-HTTP-Daemon | Jul 9, 2026 | May 27, 2026 |
| Ubuntu | — | Upgrade libhttp-daemon-perl (Ubuntu Pro)Upgrade libhttp-daemon-perl | Jun 16, 2026 | Jun 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub