CVE-2026-95831
Last modified
CVE-2026-95831 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12. For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem. The SHA-256 digests of the files are fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | >= 1.01, <= 1.05 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-95831?
How severe is CVE-2026-95831?
How do I fix CVE-2026-95831?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9582A security flaw has been discovered in SourceCodester CET Au…4.3
- CVE-2026-95820A vulnerability was found in anirbandutta9 College-Notes-Gal…6.3
- CVE-2026-95828A vulnerability was determined in Mstfakts College-Managemen…4.3
- CVE-2026-95829A vulnerability was identified in TDuckCloud tduck-platform …6.3
- CVE-2026-9583A weakness has been identified in SourceCodester CET Automat…4.3
- CVE-2026-95830A security flaw has been discovered in theRealSain Pixtream …6.3
- CVE-2026-95833A weakness has been identified in itsourcecode Leave Managem…6.3
- CVE-2026-9584A security vulnerability has been detected in code-projects …7.3
- CVE-2026-95842Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95843Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95844Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95845Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
Are you affected by CVE-2026-95831?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
