Advisories ยป MGASA-2026-0149

Updated perl-WWW-Mechanize-Cached, perl-File-XDG & perl-Path-Tiny packages fix security vulnerabilities

Publication date: 18 May 2026
Modification date: 18 May 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-8612

Description

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached
HTTP responses from a world-writable on-disk cache, enabling local
response forgery and code execution.
                

References

SRPMS

9/core