{"id":"CVE-2026-104380","title":"Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one","summary":"Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one.\n\nOn HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET …","severity":"none","cwe":["CWE-1385"],"product":"Punk","affected":["Punk >= 0.48 < 0.55"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T01:13:14.558Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-104380","references":[{"url":"https://metacpan.org/release/LNATION/Punk-0.55/diff/LNATION/Punk-0.54"},{"url":"https://metacpan.org/release/LNATION/Punk-0.55/changes"}],"tags":["cve.org"],"ingestedAt":"2026-10-06T01:38:44.801Z","slug":"CVE-2026-104380","body":"## Overview\n\nPunk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one.\n\nOn HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.\n\nA cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.\n\n## Affected\n\n- `Punk >= 0.48 < 0.55`\n\n## Remediation\n\nUpgrade to Punk 0.55 or later.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}