LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-7381 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: April 30, 2026

Plack Middleware XSendfile - Path Traversal

Published: April 29, 2026Updated: April 30, 2026Remote Exploitable

Overview

Plack::Middleware::XSendfile <= 1.0053 for Perl contains a path traversal caused by client-controlled X-Sendfile-Type and X-Accel-Mapping headers, letting remote attackers access arbitrary files via nginx reverse proxy, exploit requires crafted headers.

Severity & Score

Severity: Critical
CVSS Score: 9.1

Impact

Remote attackers can read arbitrary files on the server via nginx reverse proxy, potentially exposing sensitive information.

Mitigation

Update to a version after 1.0053 or remove usage as it is deprecated.

Details

CVE ID
CVE-2026-7381
Severity
Critical
CVSS Score
9.1
Type
path_traversal
Status
unconfirmed

CWE

  • CWE-200

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N