---
id: CVE-2026-104380
title: >-
  Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests
  to any GET route without an Origin check in ps_serve_one
summary: >-
  Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests
  to any GET route without an Origin check in ps_serve_one.


  On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT,
  which is matched as a GET …
severity: none
cwe:
  - CWE-1385
product: Punk
affected:
  - Punk >= 0.48 < 0.55
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T01:13:14.558Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-104380'
references:
  - url: 'https://metacpan.org/release/LNATION/Punk-0.55/diff/LNATION/Punk-0.54'
  - url: 'https://metacpan.org/release/LNATION/Punk-0.55/changes'
tags:
  - cve.org
ingestedAt: '2026-10-06T01:38:44.801Z'
---

## Overview

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one.

On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.

A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.

## Affected

- `Punk >= 0.48 < 0.55`

## Remediation

Upgrade to Punk 0.55 or later.
