CVE-2026-95811: Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it
Lemonldap::NG::Handler lets equivalent path spellings bypass locationRules before fixed releases (CVE-2026-95811).
The CPAN Security Group disclosed CVE-2026-95811 in Lemonldap::NG::Handler for Perl. Affected versions are 2.0.0 before 2.16.10, 2.17.0 before 2.21.6, and 2.22.0 before 2.23.4. An equivalent spelling of a path can bypass locationRules that are meant to restrict it. The oss-security post does not report in-the-wild exploitation.
- CVE-2026-95811 affects Lemonldap::NG::Handler for Perl.
- Equivalent path spellings can bypass locationRules restrictions.
- Vulnerable ranges end before 2.16.10, 2.21.6, and 2.23.4.
- The disclosure does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-958116.5—Authorization bypass via URI normalization mismatch in Lemonldap::NG Handlerpublished · Lemonldap::NG::Handler (Perl)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-95811 | Authorization bypass via URI normalization mismatch in Lemonldap::NG Handler Lemonldap::NG::Handler, the Perl reverse-proxy authentication component of the Lemonldap::NG SSO suite, evaluates each vhost's locationRules regular expressions against REQUEST_URI (the raw, still-encoded request line) while the backend web server routes on the percent-decoded and normalized path. An attacker triggers the flaw by spelling a protected URL in an equivalent form — percent-encoding a path character, inserting dot segments, or doubling a slash — so that no locationRules regexp matches and the vhost's default rule decides access. This bypasses deny rules, identity and group conditions, and unprotect and skip rules alike, letting an authenticated user reach any URL a rule was meant to restrict; the gain is capped at whatever the vhost's default rule already grants, so only vhosts with a default rule more permissive than their other rules are affected. All maintained branches are impacted, with fixes in 2.16.10, 2.21.6, and 2.23.4. No public proof of concept exists, the flaw is not in the CISA KEV catalog, and no exploitation has been reported. |
Posted by Timothy Legge on Sep 24 ======================================================================== CVE-2026-95811 CPAN Security Group ======================================================================== CVE ID: CVE-2026-95811 Distribution: Lemonldap-NG-Handler Versions: from 2.0.0 before 2.16.10 from 2.17.0 before 2.21.6 from 2.22.0 before 2.23.4 MetaCPAN:...
This source does not provide full text. Read it at seclists.org.