CVE-2026-104380 | CPANSec Punk up to 0.54 WebSocket Handshake ps_serve_one cross-domain policy

SecurityVulns

A vulnerability described as problematic has been identified in CPANSec Punk up to 0.54. Impacted is the function ps_serve_one of the component WebSocket Handshake. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is known as CVE-2026-104380. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More