CVE-2026-104380
Received Received - Intake

Cross-Site WebSocket Hijacking in Punk

Vulnerability report for CVE-2026-104380, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: CPANSec

Description

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1385 The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Punk web server versions from 0.48 before 0.55 for Perl. It involves Extended CONNECT requests being incorrectly routed to GET routes without proper Origin checks. On HTTP/2 and HTTP/3, WebSocket handshakes are treated as Extended CONNECT requests and matched to GET routes, bypassing Origin validation unless explicitly handled by a websocket route.

Impact Analysis

An attacker could exploit this to open a WebSocket connection to any path on your server from a cross-origin page. They can then determine if the path returns a 2xx status code by observing the WebSocket open or error event, potentially exposing sensitive information about your server's routes or API endpoints.

Mitigation Strategies

Upgrade Punk to version 0.55 or later to address the vulnerability in Extended CONNECT request handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104380. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart