Fedora 44 perl-Dancer2 Major Deserialization Vulnerability 2026-3b893ccf2d
Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval. deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itselfLinuxSecurity – Security AdvisoriesRead More