CVE-2026-97230
Last modified
CVE-2026-97230 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. The dropper script is in lib/Crypt/SelfCertificate/sample/cert.pem. This is similar to CVE-2026-95831 for the module Crypt::SelfCertificate. The SHA-256 digests of the files are ba24ee8ec3b7f47f65bed62e16fb413ace50653cf44bd8ea90914390922831e0 IO-Socket-SSL-SelfCertificate-1.00.tar.gz 821d38830e5eb8607738421c25ac25f59fff02a6ab67daa32fbd020429454dac IO-Socket-SSL-SelfCertificate-1.00/lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem d483cb7b23b7271cb11cf242bff4a2e1c02df0b9525eb0429abeea8961c399d5 IO-Socket-SSL-SelfCertificate-1.00-upload.tar.gz
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | 1.00 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-97230?
How severe is CVE-2026-97230?
How do I fix CVE-2026-97230?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-97222A heap use-after-free flaw was found in Gnumeric. When a use…5.5
- CVE-2026-97224A vulnerability was detected in Excalidraw up to 0.18.1. The…4.3
- CVE-2026-97225A flaw has been found in DbGate up to 7.2.5-beta.5. This aff…6.3
- CVE-2026-97226A vulnerability has been found in DbGate up to 7.2.5/7.3.1-p…6.3
- CVE-2026-97228Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer f…2.7
- CVE-2026-9723The Google Plus One Bottom plugin for WordPress is vulnerabl…4.3
- CVE-2026-97231A vulnerability was found in volotat Anagnorisis up to 0.3.1…7.3
- CVE-2026-97232A vulnerability was determined in volotat Anagnorisis up to …6.3
- CVE-2026-97233A vulnerability was identified in volotat Anagnorisis up to …3.5
- CVE-2026-9724The MotorDesk plugin for WordPress is vulnerable to Cross-Si…4.3
- CVE-2026-9725The Printcart Web to Print Product Designer for WooCommerce …9.1
- CVE-2026-9726Improperly Controlled Modification of Dynamically-Determined…9.8
Are you affected by CVE-2026-97230?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
