Bug 2502710 (CVE-2026-13577)
| Summary: | CVE-2026-13577 Dancer2: Dancer2: Predictable session IDs allow system access | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Dancer2. When Cryptographically Secure PseudoRandom Number Generator (CSPRNG) modules are not available, Dancer2 generates insecure session identifiers (IDs). This occurs because the system falls back to using a less secure, built-in random number generator. An attacker could exploit these predictable session IDs to gain unauthorized access to systems.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2509105 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-20 09:01:17 UTC
|