CVE-2026-104380: Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in psserveone.
On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.
A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Punkto a version that resolves this vulnerability.Fixed in 0.55
Event History
Frequently Asked Questions
Which deployments are exposed to this behavior?
Punk for Perl versions 0.48 through 0.54 are affected when handling WebSocket handshakes over HTTP/2 or HTTP/3. GET routes, API operations, and mounts can be reached through an Extended CONNECT request on those transports.
What does an attacker need to exploit it?
An attacker can use a cross-origin web page to open a WebSocket connection to a target path. No matching WebSocket route is required because the Extended CONNECT request is matched as a GET route.
What can an attacker learn or achieve through the affected request path?
If the reached handler returns a 2xx status, it accepts the WebSocket handshake. A cross-origin page can distinguish whether a path returns 2xx based on the WebSocket open or error event.
What version resolves the issue?
The issue affects versions before 0.55 starting with 0.48, so upgrading to Punk 0.55 removes the affected version range.