Get real-time updates on Telegram
Verified
CVE-2026-104380: Punk versions from 0.48 security flaw
Affected technology
Product not specified by the source · 0.48 to before 0.55
Vendor not specified by the source
Description’s affected range: versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one
Component: Punk
Function: ps_serve_one
File: include/punk/punk_serve.h
What an attacker can do
The source does not specify what an attacker can achieve.
- CWE
- CWE-1385
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-06 03:43:59.502831+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-06 05:27:41.925768+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104380.html