CVE-2026-104380: Punk routing flaw
An advisory published on October 5, 2026, reports that Punk for Perl versions before 0.55 may route Extended CONNECT requests to GET routes without validating the Origin header.
Source: CVE-2026-104380: Punk para Perl roteia Extended CONNECT para qualquer rota GET sem verificar Origin (seclists.org). Text prepared with AI from this source.
What happened and what to do
The CVE-2026-104380 advisory, published by Timothy Legge on October 5, 2026, in the oss-sec feed, identifies an issue in Punk for Perl versions 0.48 through those before 0.55. In these versions, Extended CONNECT requests may be routed to GET routes without checking the Origin header. The advisory identifies the distribution and affected versions; consult the original in the oss-sec feed and check the distribution and versions on MetaCPAN to verify the details.
A practical response is to inventory services using Punk, identify their versions and exposed GET routes, and plan an upgrade or mitigation compatible with the environment. The company can also monitor dependencies and version changes, and review security tests to validate handling of Origin and Extended CONNECT. This calls for dependency management and application security, not necessarily AI.
How the consultancy can help
Wendelmaques can diagnose exposure, map affected versions and services, and define a scoped plan for upgrades, mitigations, and testing. It can also implement dependency monitoring and support operation of the agreed controls.
Next step
Send a short description of the services using Punk and your Perl environment to receive a scoped proposal for diagnosis and implementation.
Consulting for your project
Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.
Quoted per project
Request a proposal