---
id: CVE-2026-5087
title: >-
  PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl
  generates random bytes insecurely.


  PAGI::Middleware::Session::Store::Cookie attempts to read bytes from the
  /dev/urandom device directly
summary: >-
  PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl
  generates random bytes insecurely.


  PAGI::Middleware::Session::Store::Cookie attempts to read bytes from the
  /dev/urandom device directly. If that fails (for exa…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-338
  - CWE-1204
vendor: jjnapiork
product: 'pagi::middleware::session::store::cookie'
affected:
  - 'pagi::middleware::session::store::cookie <= 0.001003'
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5087'
references:
  - url: >-
      https://metacpan.org/release/JJNAPIORK/PAGI-Middleware-Session-Store-Cookie-0.001003/source/lib/PAGI/Middleware/Session/Store/Cookie.pm#L156-173
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: >-
      https://metacpan.org/release/JJNAPIORK/PAGI-Middleware-Session-Store-Cookie-0.001004/changes
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'http://www.openwall.com/lists/oss-security/2026/03/31/10'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00316
epssPercentile: 0.24715
ingestedAt: '2026-07-24T20:38:02.670Z'
---

## Overview

PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely.

PAGI::Middleware::Session::Store::Cookie attempts to read bytes from the /dev/urandom device directly. If that fails (for example, on systems without the device, such as Windows), then it will emit a warning that recommends the user install Crypt::URandom, and then return a string of random bytes generated by the built-in rand function, which is unsuitable for cryptographic applications.

This modules does not use the Crypt::URandom module, and installing it will not fix the problem.

The random bytes are used for generating an initialisation vector (IV) to encrypt the cookie.

A predictable IV may make it easier for malicious users to decrypt and tamper with the session data that is stored in the cookie.

## Affected

- `pagi::middleware::session::store::cookie <= 0.001003`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
