Description
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one.
On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.
A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.
A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
Published:
2026-10-06
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to Punk 0.55 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 Oct 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx. | |
| Title | Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one | |
| Weaknesses | CWE-1385 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-10-06T01:13:14.558Z
Reserved: 2026-10-01T22:29:10.271Z
Link: CVE-2026-104380
No data.
Status : Received
Published: 2026-10-06T02:17:03.910
Modified: 2026-10-06T02:17:03.910
Link: CVE-2026-104380
No data.
OpenCVE Enrichment
Updated: 2026-10-06T02:30:18Z
Weaknesses