Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler.

The handler joins the request path onto public_dir without collapsing relative segments, and checks only that the result is a readable regular file. A request for `/../outside.txt` escapes public_dir, and percent-encoding the dots reaches the same file.

The handler is off by default. An application is affected once it names File in route_handlers and sets static_handler to 0, which otherwise refuses a dot segment before the route runs.

Any file the worker process can read is served to an unauthenticated request, including the application's config.yml above public_dir.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade to Dancer2 2.2.0 or later.


Workaround

No workaround given by the vendor.

History

Tue, 22 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and checks only that the result is a readable regular file. A request for `/../outside.txt` escapes public_dir, and percent-encoding the dots reaches the same file. The handler is off by default. An application is affected once it names File in route_handlers and sets static_handler to 0, which otherwise refuses a dot segment before the route runs. Any file the worker process can read is served to an unauthenticated request, including the application's config.yml above public_dir.
Title Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler
Weaknesses CWE-22
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-22T02:09:48.478Z

Reserved: 2026-09-18T15:07:22.163Z

Link: CVE-2026-93712

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T01:16:55.957

Modified: 2026-09-22T01:16:55.957

Link: CVE-2026-93712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T02:30:07Z

Weaknesses