On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.
A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to Punk 0.55 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perl
Perl punk |
|
| Vendors & Products |
Perl
Perl punk |
Tue, 06 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 06 Oct 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 06 Oct 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx. | |
| Title | Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one | |
| Weaknesses | CWE-1385 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-10-06T13:14:39.875Z
Reserved: 2026-10-01T22:29:10.271Z
Link: CVE-2026-104380
Updated: 2026-10-06T05:07:59.987Z
Status : Deferred
Published: 2026-10-06T02:17:03.910
Modified: 2026-10-06T15:03:59.427
Link: CVE-2026-104380
No data.
OpenCVE Enrichment
Updated: 2026-10-07T06:15:12Z