{
  "id": "CVE-2026-104380",
  "url": "https://spydr.io/cve/CVE-2026-104380",
  "published": "2026-10-06T02:17:03.910Z",
  "modified": "2026-10-06T15:03:59.427Z",
  "score": 5.3,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "score_source": "CISA ADP",
  "epss": null,
  "epss_percentile": null,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [],
  "products": [],
  "cwes": [
    "CWE-1385"
  ],
  "description": "Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.",
  "status": "Deferred",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.3,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://metacpan.org/release/LNATION/Punk-0.55/changes",
      "tags": []
    },
    {
      "url": "https://metacpan.org/release/LNATION/Punk-0.55/diff/LNATION/Punk-0.54",
      "tags": []
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/10/06/1",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-104380",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
