Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-7381— Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting

EPSS 0.01% · P2
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-7381

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting
Source: NVD (National Vulnerability Database)
Vulnerability Description
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the "X-Accel-Redirect" type.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Plack::Middleware::XSendfile 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Plack::Middleware::XSendfile是MIYAGAWA个人开发者的一个为Web应用提供高效文件传输支持的中间件组件。 Plack::Middleware::XSendfile 1.0053及之前版本存在信息泄露漏洞,该漏洞源于允许客户端通过X-Sendfile-Type标头控制路径重写,可能导致恶意客户端设置X-Accel-Redirect类型并映射到任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MIYAGAWAPlack::Middleware::XSendfile 0 ~ 1.0053 -

II. Public POCs for CVE-2026-7381

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-7381

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-7381

No comments yet


Leave a comment