Re: CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone
A follow-up corrects the VCS repository cited for Catalyst::Seal CVE-2026-85491, citing bad module metadata.
Robert Rothenberg posted a short correction to the CVE-2026-85491 disclosure for the Perl module Catalyst::Seal. He said the version-control repository cited earlier is incorrect and came from bad metadata associated with the module. The note does not add exploitation details or a new fix. The subject line still describes the pre-0.03 authorization-bypass issue.