CVE-2026-5081
CHORNY Apache::Session::Generate::ModUniqueId, Red Hat Hardened Images, apache::session::generate::moduniqueid
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_ID environment variable for the session id. The UNIQUE_ID variable is set by the Apache mod_unique_id plugin, which generates unique ids for the request. The id is based on the IPv4 address, the process id, the epoch time, a 16-bit counter and a thread index, with no obfuscation. The server IP is often available to the public, and if not available, can be guessed from previous session ids being i...
- CVSS
- 9.1
- EPSS
- 0.30% 22.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.06