Bug 2520677 (CVE-2026-15743)

Summary: CVE-2026-15743 perl-Catalyst-Plugin-Static-Simple: Catalyst::Plugin::Static::Simple: Information disclosure via public caching of authenticated responses
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Catalyst::Plugin::Static::Simple for Perl. The _serve_static method incorrectly sets the Cache-Control header to "public" for all responses. This misconfiguration allows intermediate proxies to store sensitive content, including responses from authenticated sessions, in shared caches. Consequently, an attacker could potentially access confidential information intended for other users, leading to unauthorized information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2536982    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-20 18:22:29 UTC
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable.

The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it.  This advises proxies that the content may be stored in a shared cache, and may be reused in responses to requests from other users. (This includes requests with an Authorization header.)

Configuring the expires time to "0" to disable caching, as documented, is ignored.